test 1 Flashcards
how many field extraction methods are there?
2
regular expression and delimiters
which command allows to perform search existing data models and their datasets from the search interface?
datamodel
by default what is the number of events per transaction?
1000
‘Event Type’ comes seventh in the search-time operations order
correct
it is a must to specify a statistical function when using the chart command
Correct
how many search types affect Splunk performance
4
Dense up to 50000 matching EPS
Sparse up to 5000 matching EPS
Super Sparse up to 2 seconds per index bucket
Rare from 10 to 20 index buckets per second
Splunk software knowledge can be grouped into how many categories?
5
Data interpretation– fields and field ectractions
Data Classification– Event Types and transactions
Data Enrichment– lookups and workflow actions
Data Normalisation– Tags and Aliases
Data Models
data model editor groups datasets into how many categories?
3
field extractions, lookups and eval expressions
a data model consist of how many categories?
3
Is it possible to apply field aliases to lookup?
No
True or False
Only root events can be accelerated
True
True or False
data model name and dataset name are case sensitive
True
Where is the occurrence of tags in the sequence of search time operations?
Last
true or false
the power user can create an object that persists across all apps
False
True or False
It is not possible to apply field aliases to lookups
False