Loading questions...
Updated
Portal for Splunk apps can be accessed through www.splunkbase.com
Splunk shows data in __________________.
Which of the following can be used as wildcard search in Splunk?
What result will you get with following search index=test sourcetype="The_Questionnaire_P*" ?
Prefix wildcards might cause performance issues.
Machine data can be in structured and unstructured format.
Field names are case sensitive.
Splunk internal fields contains general information about events and starts from underscore i.e. _ .
How many main user roles do you have in Splunk?
Which of the following are Splunk premium enhanced solutions? (Choose three.)
When running searches, command modifiers in the search string are displayed in what color?
Fields are searchable name and value pairings that differentiates one event from another.
Splunk extracts fields from event data at index time and at search time.
Field values are case sensitive.
Splunk indexes the data on the basis of timestamps.
______________ is the default web port used by Splunk.
Which of the following statements are correct about Search & Reporting App? (Choose three.)
Parsing of data can happen both in HF and Indexer.
Monitor option in Add Data provides _______________.
License Meter runs before data compression.
Forward Option gather and forward data to indexers over a receiving port from remote machines.
Which of the following represents the Splunk recommended naming convention for dashboards?
You can on-board data to Splunk using following means (Choose four.):
Which search string only returns events from hostWWW3?
When editing a dashboard, which of the following are possible options? (Choose all that apply.)