Top Values by time
What are the two most efficient search filters?
B
Which of the following is a metadata field assigned to every event in Splunk?
A
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Assignmetadatatoeventsdynamically
Assuming a user has the capability to edit reports, which of the following are editable?
B
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.3/Report/Createandeditreports
What is a quick, comprehensive way to learn what data is present in a Splunk deployment?
C
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.3/InheritedDeployment/Yourdata
When viewing results of a search job from the Activity menu, which of the following is displayed?
C
Which of the following is a correct way to limit search results to display the 5 most common values of
a field?
C
Which of the following is the most efficient search?
A
Which command will rename action to Customer Action?
D
Explanation:
Reference:
https://answers.splunk.com/answers/610038/understanding-command-in-search.html
Which of the following is a Splunk internal field?
A
What is the correct way to use a time range specifier in the search bar so that the search looks back 2
hours?
B
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.3/Search/Specifytimemodifiersinyoursearch
What will always appear in the Selected Fields list?
D
In the Search and Reporting app, which tab displays timecharts and bar charts?
D
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.2/Search/Aboutreportingcommands
Which of the following reports is available in the Fields window?
C
Top Values by time
Which search will return only events containing the word error and display the results as a table
that includes
the fields named action, src, and dest?
C
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.3/SearchReference/search
Which of the following statements describes a search job?
D
Explanation:
Reference:
https://answers.splunk.com/answers/329699/why-does-my-search-head-cluster-captain-start-dele-1.html