test 1 Flashcards

1
Q

how many field extraction methods are there?

A

2

regular expression and delimiters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

which command allows to perform search existing data models and their datasets from the search interface?

A

datamodel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

by default what is the number of events per transaction?

A

1000

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

‘Event Type’ comes seventh in the search-time operations order

A

correct

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

it is a must to specify a statistical function when using the chart command

A

Correct

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

how many search types affect Splunk performance

A

4
Dense up to 50000 matching EPS
Sparse up to 5000 matching EPS
Super Sparse up to 2 seconds per index bucket
Rare from 10 to 20 index buckets per second

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Splunk software knowledge can be grouped into how many categories?

A

5
Data interpretation– fields and field ectractions
Data Classification– Event Types and transactions
Data Enrichment– lookups and workflow actions
Data Normalisation– Tags and Aliases
Data Models

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

data model editor groups datasets into how many categories?

A

3

field extractions, lookups and eval expressions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

a data model consist of how many categories?

A

3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Is it possible to apply field aliases to lookup?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

True or False

Only root events can be accelerated

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

True or False

data model name and dataset name are case sensitive

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Where is the occurrence of tags in the sequence of search time operations?

A

Last

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

true or false

the power user can create an object that persists across all apps

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

True or False

It is not possible to apply field aliases to lookups

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

True or False

as with chart, it is possible to split timechart by 2 fields

A

False

17
Q

what does the gauge command allow you to do

A

set coloured ranges for a single-value visualisation

18
Q

what allows you to categorise events based on search terms

A

Event Types

19
Q

The time range specified for a historical search defines the……

A

amount of data fetched from the index matching that time range

20
Q

what clause is used to group the output of a stats command by a specific name

A

Rex

21
Q

when a search returns______, you can view the results as a list

A

statistical values

22
Q

which function should you use with the transaction command to set the maximum total time between the earliest and latest events

A

maxspan

23
Q

what attributes are required to create a POST workflow action?

A

XML attributes, URL, name

24
Q

In what order are knowledge object/configurations applied?

A

Field Extraction, Lookups, Field Aliases

25
Q

Can Auto-Extracted fields have their data type changed?

A

YES

26
Q

True or False

A Macro is a reusable search string that may have a flexible time range

A

True

27
Q

What happens when you click on a SEGMENT on a chart?

A

Adds the highlighted value to the search criteria

28
Q

True or False
Useother=f
Split=t
Are valid options in the chart command

A

FALSE

29
Q

What format does the CIM Add-on data models include?

A

JSON

30
Q

When a search returns ________, you can view the results as a list

A

Statistical Values

31
Q

True or False

Users can define the time range of the search when created the workflow action?

A

True