Exam A+ Pass Verified
What is the only writeable bucket type?
hot bucket
warm bucket
cold bucket - Answer- The hot bucket
By what filter are indexes divided into buckets?
by time
by name
by source
by host - Answer- By time
What are the 4 types of searches in Splunk (by performance)
dense
sparse
super sparse
rare
super rare - Answer- Dense, Sparse, Super Sparse, Rare
In searches, what is the scanCount?
the number of scanned events for all searches
the number of events scanned for that particular search
none of the above - Answer- The number of events scanned for that particular search
What are the requirement of the underlying search in order to get multi-series table? -
Answer- The underlying search must use reporting search commands like chart or
timechart
What are the seven chart types? - Answer- Line, Area, Column, Bar, Bubble, Scatter
and Pie
What is a trait of scatter charts? - Answer- Can only show two dimensions. Shows
trends in the relationsgip between discrete data values
What is a trait of bubble charts? - Answer- Provides a visual way to view a three
dimensional series
What are two commonly used clauses for chart? - Answer- over and by
What does the over and by clauses do when used with chart? - Answer- divides the
data into sub-groupings
, (True/False) You can only split chart results over two dimensions - Answer- True
chart and timechart commands automatically filter results to include how many values? -
Answer- 10
What happens to surplus resulting values of chart and timechart commands? - Answer-
They are grouped into other
(True/False) Null values are not shown by default by chart and timechart - Answer-
False
What is always the value on the x-axis for timechart? - Answer- _time
(True/False) Functions and arguments used with stats and chart can not be used with
timechart - Answer- False
(True/False) As with chart, it is possible to split timechart by two fields - Answer- False.
It is only possible to split by one field
What is the argument for adjusting sampling interval of timechart? - Answer- span
What does the trendline command do? - Answer- allows you to overlay a computed
moving average on a chart
What is the syntax of the trendline command? - Answer- trendline
<trendtype><period>(field) [AS newfield]
What command can be used to look up and add location information to an event? -
Answer- iploaction
What information does the iplocation command include? - Answer- city, country, region,
latitude and longitude
What is the data-requirement for the geostats command? - Answer- Data must include
latitude and longitude values
These arguments are used to control column counts when using the geostats command
- Answer- gloabllimit and locallimit
This command is used to compute statisticalm functions and render a cluster map -
Answer- geostats
What command can be used to show relative metrics for predefined geographic
regions? - Answer- geom