/
Splunk Core Concepts Review
Save to my account
Sign up
Splunk Core Concepts Review
Splunk Core Concepts Review
Study
1
Question
What is the language of the provided PDF content?
Answer
English
2
Question
True or False: Machine data is always structured.
Answer
False
3
Question
True or False: Machine data is only generated by web servers.
Answer
False
4
Question
Machine data makes up more than what percentage of data accumulated by organizations?
Answer
90%
5
Question
Where are search requests processed in Splunk?
Answer
Indexers
6
Question
From where are search strings sent in Splunk?
Answer
From the Search Head to the Indexers
7
Question
In most Splunk deployments, what serve as the primary data indexing input?
Answer
Forwarders
8
Question
Which of these is not a main component of Splunk? A) Search and investigate, B) Compress and archive, C) Add knowledge, D) Collect and index data
Answer
B) Compress and archive
9
Question
What are the three main processing components of Splunk? (Select all that apply)
Answer
Indexers, Search Heads, Forwarders
10
Question
What defines what users can do in Splunk?
Answer
Roles
11
Question
Which roll will only see their own knowledge objects and those shared with them?
Answer
User
12
Question
True or False: You can launch and manage apps from the home app.
Answer
True
13
Question
What are the three main default roles in Splunk Enterprise? (Select all that apply)
Answer
User, Admin, Power
14
Question
Which apps ship with Splunk Enterprise? (Select all that apply)
Answer
Home App, Search & Reporting
15
Question
What is the default username and password for a newly installed Splunk instance?
Answer
admin and changeme
16
Question
Files indexed using the upload input option get indexed how often?
Answer
Once
17
Question
True or False: The monitor input option will allow you to continuously monitor files.
Answer
True
18
Question
Splunk knows where to break the event, where the time stamp is located and how to automatically create field value pairs using these. What are these?
Answer
Source types
19
Question
Splunk uses what to categorize the type of data being indexed?
Answer
Source types
20
Question
In most production environments, what will be Forwarders the source of data input?
Answer
Forwarders
21
Question
How is the asterisk used in Splunk search?
Answer
As a wildcard
22
Question
Which search mode toggles behavior based on the type of search being run?
Answer
Smart
23
Question
When zooming in on the event timeline, does a new search run?
Answer
False
24
Question
Which searches will return the same results? (failed password, failed AND password)
Answer
Failed AND password will return the same as failed password in some contexts
25
Question
A search job will remain active for how many minutes after it is run?
Answer
10
26
Question
What attributes describe the field below? a dest 4 (Select all that apply)
Answer
Contains 4 values; Contains numerical values; Contains string values
27
Question
True or False: Wildcards cannot be used with field searches.
Answer
False
28
Question
Are field values case sensitive?
Answer
False (field values are not case sensitive)
29
Question
Which is not a comparison operator in Splunk? A) >, B) =?, C) <=, D) !=, E) =
Answer
B) ?=
30
Question
Field names are what in Splunk? (Select all that apply)
Answer
Case sensitive; Not important in Splunk; Can be case sensitive or case insensitive depending on context