EXAM TOPIC IV
You can view the search results in following format: - ANS-1. Table
2. Raw
3. List
The data summary button just below the search bar gives you the following: - ANS-1. Hosts
2. Sourcetypes
3. Sources
How to make Interesting field into a selected field? - ANS-1. Click field in field sidebar
2. Click YES on the pop-up dialog on upper right side.
"search best practices" in Splunk - ANS-1. Select the time range always
2. Try to specify index values.
3. Include as many search terms as possible.
4. Inclusion is generally better than exclusion.
5. Try to keep specific search terms.
Put query into separate lines where | (Pipes) are used by selecting following options. -
ANS-Shift + Enter
What are the time selection options while making search? - ANS-A. Date & Time Range
B. Advanced
C. Date Range
D. Presets
E. Relative
When viewing results of a search job from the Activity menu, which of the following is displayed?
- ANS-The same events from when the original search was executed.
What is a quick, comprehensive way to learn what data is present in a Splunk deployment? -
ANS-Click Data Summary in Splunk Web
When is the pipe character, I, used in search strings? - ANS-Before commands.
For example | stats sum(bytes) by host
In the Fields sidebar, what does the number directly to the right of the field name indicate? -
ANS-The number of unique values for the field
You can view the search results in following format: - ANS-1. Table
2. Raw
3. List
The data summary button just below the search bar gives you the following: - ANS-1. Hosts
2. Sourcetypes
3. Sources
How to make Interesting field into a selected field? - ANS-1. Click field in field sidebar
2. Click YES on the pop-up dialog on upper right side.
"search best practices" in Splunk - ANS-1. Select the time range always
2. Try to specify index values.
3. Include as many search terms as possible.
4. Inclusion is generally better than exclusion.
5. Try to keep specific search terms.
Put query into separate lines where | (Pipes) are used by selecting following options. -
ANS-Shift + Enter
What are the time selection options while making search? - ANS-A. Date & Time Range
B. Advanced
C. Date Range
D. Presets
E. Relative
When viewing results of a search job from the Activity menu, which of the following is displayed?
- ANS-The same events from when the original search was executed.
What is a quick, comprehensive way to learn what data is present in a Splunk deployment? -
ANS-Click Data Summary in Splunk Web
When is the pipe character, I, used in search strings? - ANS-Before commands.
For example | stats sum(bytes) by host
In the Fields sidebar, what does the number directly to the right of the field name indicate? -
ANS-The number of unique values for the field