Splunk core certified user exam |\ |\ |\ |\ |\
questions with answers |\ |\
The new result after selecting the range by dragging
|\ |\ |\ |\ |\ |\ |\ |\ |\
filters the events and displays the most recent first -
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\
CORRECT ANSWERS ✔✔Which of the statements is |\ |\ |\ |\ |\ |\ |\
correct regarding click and drag option in timeline?
|\ |\ |\ |\ |\ |\ |\
Zoom to selection: Narrows the time range and re-
|\ |\ |\ |\ |\ |\ |\ |\
executes the search. |\ |\
Format Timeline: Hides or shows the timeline in different
|\ |\ |\ |\ |\ |\ |\ |\ |\
views
Zoom-out: Expands the time focus and re-executes the |\ |\ |\ |\ |\ |\ |\ |\
search - CORRECT ANSWERS ✔✔Which of the statements
|\ |\ |\ |\ |\ |\ |\ |\
are correct?
|\
False - CORRECT ANSWERS ✔✔The default host name
|\ |\ |\ |\ |\ |\ |\ |\
used in Inputs general settings can not be changed.
|\ |\ |\ |\ |\ |\ |\ |\
earliest=
latest= - CORRECT ANSWERS ✔✔You can use the
|\ |\ |\ |\ |\ |\ |\ |\
following options to specify start and end time for the
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\
query range: |\
,True - CORRECT ANSWERS ✔✔Zoom Out and Zoom to
|\ |\ |\ |\ |\ |\ |\ |\ |\
Selection re-executes the search |\ |\ |\
True - CORRECT ANSWERS ✔✔Search Assistant is enabled
|\ |\ |\ |\ |\ |\ |\
by default in the SPL editor with compact settings.
|\ |\ |\ |\ |\ |\ |\ |\ |\
Indexer - CORRECT ANSWERS ✔✔Where does Licensing
|\ |\ |\ |\ |\ |\ |\
meter happen? |\
False - CORRECT ANSWERS ✔✔Upload option creates
|\ |\ |\ |\ |\ |\ |\
inputs.conf
Filed & Directories, HTTP Event Collector (HEC), TCP/UDP
|\ |\ |\ |\ |\ |\ |\ |\
and Scripts - CORRECT ANSWERS ✔✔In monitor option
|\ |\ |\ |\ |\ |\ |\ |\
you can select the following options in GUI.
|\ |\ |\ |\ |\ |\ |\
CLI |\
Splunk Web |\
Splunk apps and add-ons |\ |\ |\
inputs.conf - CORRECT ANSWERS ✔✔You can on-board |\ |\ |\ |\ |\ |\ |\
data to Splunk using following means
|\ |\ |\ |\ |\
Input Phase - CORRECT ANSWERS ✔✔Data sources being
|\ |\ |\ |\ |\ |\ |\ |\
opened and read applies to |\ |\ |\ |\
, Can be accessed by Apps > Search & Reporting.
|\ |\ |\ |\ |\ |\ |\ |\
Provides default interface for searching and analyzing
|\ |\ |\ |\ |\ |\ |\ |\
logs.
Enables the user to create knowledge object, reports,
|\ |\ |\ |\ |\ |\ |\ |\ |\
alerts and dashboards. - CORRECT ANSWERS ✔✔Which of
|\ |\ |\ |\ |\ |\ |\ |\
the following statements are correct about Search &
|\ |\ |\ |\ |\ |\ |\ |\
Reporting App? |\
Both One-time and continuous monitoring - CORRECT
|\ |\ |\ |\ |\ |\ |\
ANSWERS ✔✔Monitor option in Add Data provides |\ |\ |\ |\ |\ |\
True - CORRECT ANSWERS ✔✔License Meter runs before
|\ |\ |\ |\ |\ |\ |\ |\
data compression |\
Splunk User Behavior Analytics (UBA)
|\ |\ |\ |\
|\ Splunk IT Service Intelligence (ITSI)
|\ |\ |\ |\
Splunk Enterprise Security (ES) - CORRECT ANSWERS
|\ |\ |\ |\ |\ |\ |\ |\
✔✔Which of the following are Splunk premium enhanced
|\ |\ |\ |\ |\ |\ |\ |\
solutions?
True - CORRECT ANSWERS ✔✔Fields are searchable name
|\ |\ |\ |\ |\ |\ |\ |\
and value pairings that differentiates one event from
|\ |\ |\ |\ |\ |\ |\ |\
another.
questions with answers |\ |\
The new result after selecting the range by dragging
|\ |\ |\ |\ |\ |\ |\ |\ |\
filters the events and displays the most recent first -
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\
CORRECT ANSWERS ✔✔Which of the statements is |\ |\ |\ |\ |\ |\ |\
correct regarding click and drag option in timeline?
|\ |\ |\ |\ |\ |\ |\
Zoom to selection: Narrows the time range and re-
|\ |\ |\ |\ |\ |\ |\ |\
executes the search. |\ |\
Format Timeline: Hides or shows the timeline in different
|\ |\ |\ |\ |\ |\ |\ |\ |\
views
Zoom-out: Expands the time focus and re-executes the |\ |\ |\ |\ |\ |\ |\ |\
search - CORRECT ANSWERS ✔✔Which of the statements
|\ |\ |\ |\ |\ |\ |\ |\
are correct?
|\
False - CORRECT ANSWERS ✔✔The default host name
|\ |\ |\ |\ |\ |\ |\ |\
used in Inputs general settings can not be changed.
|\ |\ |\ |\ |\ |\ |\ |\
earliest=
latest= - CORRECT ANSWERS ✔✔You can use the
|\ |\ |\ |\ |\ |\ |\ |\
following options to specify start and end time for the
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\
query range: |\
,True - CORRECT ANSWERS ✔✔Zoom Out and Zoom to
|\ |\ |\ |\ |\ |\ |\ |\ |\
Selection re-executes the search |\ |\ |\
True - CORRECT ANSWERS ✔✔Search Assistant is enabled
|\ |\ |\ |\ |\ |\ |\
by default in the SPL editor with compact settings.
|\ |\ |\ |\ |\ |\ |\ |\ |\
Indexer - CORRECT ANSWERS ✔✔Where does Licensing
|\ |\ |\ |\ |\ |\ |\
meter happen? |\
False - CORRECT ANSWERS ✔✔Upload option creates
|\ |\ |\ |\ |\ |\ |\
inputs.conf
Filed & Directories, HTTP Event Collector (HEC), TCP/UDP
|\ |\ |\ |\ |\ |\ |\ |\
and Scripts - CORRECT ANSWERS ✔✔In monitor option
|\ |\ |\ |\ |\ |\ |\ |\
you can select the following options in GUI.
|\ |\ |\ |\ |\ |\ |\
CLI |\
Splunk Web |\
Splunk apps and add-ons |\ |\ |\
inputs.conf - CORRECT ANSWERS ✔✔You can on-board |\ |\ |\ |\ |\ |\ |\
data to Splunk using following means
|\ |\ |\ |\ |\
Input Phase - CORRECT ANSWERS ✔✔Data sources being
|\ |\ |\ |\ |\ |\ |\ |\
opened and read applies to |\ |\ |\ |\
, Can be accessed by Apps > Search & Reporting.
|\ |\ |\ |\ |\ |\ |\ |\
Provides default interface for searching and analyzing
|\ |\ |\ |\ |\ |\ |\ |\
logs.
Enables the user to create knowledge object, reports,
|\ |\ |\ |\ |\ |\ |\ |\ |\
alerts and dashboards. - CORRECT ANSWERS ✔✔Which of
|\ |\ |\ |\ |\ |\ |\ |\
the following statements are correct about Search &
|\ |\ |\ |\ |\ |\ |\ |\
Reporting App? |\
Both One-time and continuous monitoring - CORRECT
|\ |\ |\ |\ |\ |\ |\
ANSWERS ✔✔Monitor option in Add Data provides |\ |\ |\ |\ |\ |\
True - CORRECT ANSWERS ✔✔License Meter runs before
|\ |\ |\ |\ |\ |\ |\ |\
data compression |\
Splunk User Behavior Analytics (UBA)
|\ |\ |\ |\
|\ Splunk IT Service Intelligence (ITSI)
|\ |\ |\ |\
Splunk Enterprise Security (ES) - CORRECT ANSWERS
|\ |\ |\ |\ |\ |\ |\ |\
✔✔Which of the following are Splunk premium enhanced
|\ |\ |\ |\ |\ |\ |\ |\
solutions?
True - CORRECT ANSWERS ✔✔Fields are searchable name
|\ |\ |\ |\ |\ |\ |\ |\
and value pairings that differentiates one event from
|\ |\ |\ |\ |\ |\ |\ |\
another.