Splunk User Certification Exam 133 Questions with Answers 2023
5 Main components of Splunk ES - CORRECT ANSWER Index Data, Search & investigate, Add knowledge, Monitor & Alert, Report & Analyze.
Three main rol
...
Splunk User Certification Exam 133 Questions with Answers 2023
5 Main components of Splunk ES - CORRECT ANSWER Index Data, Search & investigate, Add knowledge, Monitor & Alert, Report & Analyze.
Three main roles in splunk? (3) - CORRECT ANSWER Admin, Power, User
Installs apps, creates knowledge objects for all users (what apps a user will see by default) - CORRECT ANSWER Admin
Creates and shares knowledge objects for users of app, real-time searches - CORRECT ANSWER Power User
Only sees own knowledge objects and those shared to them - CORRECT ANSWER User
Apps in Splunk? - CORRECT ANSWER 1. Pre-built dashboards, reports, alerts and workflows
2. In-depth data analysis for power users
3. Search & Reporting
What does the search and reporting app do in splunk? - CORRECT ANSWER Creates knowledge objects, reports, and dashboards
The seven main components in splunk searching and reporting? - CORRECT ANSWER 1. Splunk bar
2. App bar
3. Search bar
4. Time range picker
5. How to search panel
6. What to search panel
7. Search History
What does the time range picker do? - CORRECT ANSWER Allow search by preset times, relative times. Real time (earliest, latest), date range. Retrieve events over a specific time period.
Limiting search by ___________ is key to faster results and is a best practice - CORRECT ANSWER time
The time range picker is set to _________ by default. - CORRECT ANSWER All-time
Search jobs are available for ____ minutes by default. - CORRECT ANSWER 10
________ commands create statistics and visualizations. - CORRECT ANSWER Transforming
________ tab is default tab for searches - CORRECT ANSWER Event
The three main search modes? - CORRECT ANSWER Fast, Verbose, and Smart
_______ mode has discovery off for event searches. No event or field data for stats searches. - CORRECT ANSWER Fast
______ mode has all events and field data; switches to this mode after visualization - CORRECT ANSWER Verbose
______ mode (default-based on search string data) has field discovery ON for event searches. No event or field data for stats searches. - CORRECT ANSWER Smart
What does the "Job V" action button do - CORRECT ANSWER Edits job settings, sends jobs to the background, inspects and deletes job.
Saved searches are set to ______ by default. - CORRECT ANSWER private
Timestamp seen in events is based on______setting in user account profile - CORRECT ANSWER time zone
List the three booleans - CORRECT ANSWER AND OR NOT
________boolean is used if none is implied - CORRECT ANSWER AND
Exact phrases use______ - CORRECT ANSWER quotes
Use a _______ for searching a string with quotes in the string - CORRECT ANSWER Backslash
Example: info="user "chrisV4" not in database" info="user\"chrisV4\" not in database "
The three default search fields automatically selected are - CORRECT ANSWER Source, Host, Sourcetype
_______ sidebar shows all fields extracted at search time - CORRECT ANSWER Fields
_______ fields that appear by default are host, sourcetype, source - CORRECT ANSWER Selected
_______ fields have values in at least 20% of the events - CORRECT ANSWER Interesting
Clicking on a field shows a list of _______, ________, and ________. - CORRECT ANSWER values, count, and percentage
These fields can launch a quick report by clicking on them (4) - CORRECT ANSWER top values, top values by time, rare values, events with this field
Use ______ to limit search to only one sourcetype - CORRECT ANSWER sourcetype=
_____ are case sensitive, _______ case insensitive - CORRECT ANSWER field names, field values
These symbols are only used with numerical values? - CORRECT ANSWER > >= < <= -->
(T/F) Using NOT and != would return the same results. - CORRECT ANSWER True
Use _______ to nest boolean searches - CORRECT ANSWER parenthesis
______ is better than exclusion - CORRECT ANSWER inclusion
When creating reports you can edit, clone, embed, and delete under the ______ tab - CORRECT ANSWER report
Creates charts, computes statistics, and formats - CORRECT ANSWER search commands
Top command returns top ____ results with a count and percentage - CORRECT ANSWER 10
What are the three ways to create visualizations? - CORRECT ANSWER 1. Select a field from the fields sidebar
2. Use the pivot interface
3. Use the Splunk search language commands in the search bar with statistics and visualization tabs
Save visual reports as _______ or _______ - CORRECT ANSWER report or dashboard pannel
________ is an action that a saved search triggers based on the results of the search - CORRECT ANSWER Alert
________ designs reports into a simple interface without having to craft a search string - CORRECT ANSWER Pivot
The default time value for pivot is ______ - CORRECT ANSWER all the time
The data model is the framework and the ______ is the interface to the data - CORRECT ANSWER pivot
_______ object is the main source of data - CORRECT ANSWER Root
_______ object acts like an AND boolean - CORRECT ANSWER Child
(T/F) An instant pivot allows instant access to data without having a data model - CORRECT ANSWER True
alerts use a _______ search to check for events. - CORRECT ANSWER saved
Adjust the ______ type to configure how often the search runs - CORRECT ANSWER alert
Use ________ alerts to check for events on a regular basis - CORRECT ANSWER Scheduled
_______ alerts monitor for events continuously - CORRECT ANSWER Real-time
An _______ action can notify you of a triggered alert and help you start responding to it - CORRECT ANSWER alert
Search terms include (6) - CORRECT ANSWER Keywords, booleans, phrases, fields, wildcards, and comparisons.
______ is the most efficient filter - CORRECT ANSWER Time
Search terms are case sensitive or case insensitive.
(components of search language) - CORRECT ANSWER Case insensitive
______ tell Splunk what we want to do with results (ex. stats)
(components of search language) - CORRECT ANSWER Commands
______ are how we deal with results (ex. list)
(components of search language) - CORRECT ANSWER Functions
______ are variables to apply to function (ex. Product name)
(components of search language) - CORRECT ANSWER Arguments
_______ are how we want results defined.
(components of search language) - CORRECT ANSWER Clauses
_____ is used to pass current results to the next search component - CORRECT ANSWER A pipe
(T/F) Search command works from left to right - CORRECT ANSWER True
(T/F) Once an item is filtered out it is no longer available in the search string - CORRECT ANSWER True
_____ command includes or excludes fields from search results. - CORRECT ANSWER Fields
Exclude a field by using ______ symbol - CORRECT ANSWER minus (-)
(T/F) Primary fields _time and _raw will always be extracted, but can also be removed by using the minus symbol - CORRECT ANSWER True
Field_____happens after field______only affecting displayed results. - CORRECT ANSWER exclusion, extraction
________ command retains searched data in a tabulated format - CORRECT ANSWER table
(T/F) In regards to a rename command, once a field is renamed the original name is available to later search commands - CORRECT ANSWER F
This command removes events with duplicate values - CORRECT ANSWER dedup
This command displays results in ascending or descending order. - CORRECT ANSWER sort
This command combines fields from external sources to searched events, based on event field - CORRECT ANSWER Lookup
This command produces statistics of a search result - CORRECT ANSWER stats command
This command shows the number of events matching search criteria - CORRECT ANSWER stats count
This command is the sum of numerical value - CORRECT ANSWER stats sum command
This command preforms stats aggregation against time - CORRECT ANSWER timechart command
___ split data by an additional field - CORRECT ANSWER by
(T/F) Usenull = _____ will remove NULL values - CORRECT ANSWER False
Produces additional fields such as duration and event count - CORRECT ANSWER Transaction command
fillnull Command i.e. fillnull value=NULL - CORRECT ANSWER Replaces null values in fields using value=string
Indexes data, files into directories by age - CORRECT ANSWER Indexer
Uses Splunk search language, distributes search requests to indexers. Contains reports, dashboards, and visualizations - CORRECT ANSWER Search heads
Consumes and sends data to the indexer - CORRECT ANSWER Forwaders
Splunk's way of categorizing the type of data, knowing where to break the event. location of time stamp, and create field pairs - CORRECT ANSWER sourcetype
Watches files, directories, http events etc - CORRECT ANSWER Monitor (add data)
Are case insensitive and *wildcard supported - CORRECT ANSWER Search terms
Booleans - in orange - CORRECT ANSWER AND, OR, NOT in this order (AND is implied) and must be uppercase
Has the following: timestamp, host, source, sourcetype - CORRECT ANSWER Event details
Can set read permissions, lifetime, and link to a job - CORRECT ANSWER Job settings
Searchable key/value pairs in your event data. They are case sensitive - CORRECT ANSWER Fields
A set of configurable fields displayed for each event. Field names are case sensitive - field values are not - CORRECT ANSWER Search fields
Occur in at least 20% of resulting events - CORRECT ANSWER Interesting fields
Looks back to the designated earliest event - CORRECT ANSWER earliest i.e. earliest=-hr
Looks to the ending time range. The @ snaps to the time period defined - CORRECT ANSWER latest i.e. latest=@d
A location where Splunk stores and searches for event data - CORRECT ANSWER Indexer
This role segregates data into separate indexes to limit access by Splunk role - CORRECT ANSWER Administrators
Search component that define what you are looking for - keywords, phrases Booleans, etc. These are case insensitive - CORRECT ANSWER Search terms
Search component that defines what you want to do with the results -- create a chart, compute statistics, evaluate and format, etc - CORRECT ANSWER Commands (blue)
Search component that defines how you want to chart, compute, or evaluate results - get sum, get an average, transform the values, etc - CORRECT ANSWER Functions (purple)
Are variables that you can apply to functions -- can calculate average value for a specific field, convert milliseconds to seconds, etc - CORRECT ANSWER Arguments (green)
Determines how you want to group or name the fields in the results, can give the field another name or group values by or over - CORRECT ANSWER Clauses
The command that returns a table formed only by the fields in the argument list. Each row is an event and each argument is a column - CORRECT ANSWER table {| table clientip, action, status}
When used with "as" chnages the name of a field - CORRECT ANSWER rename {| rename productid as ProductID}
The command that allows you to include or exclude specified fields in your search or report - CORRECT ANSWER fields +(default) - {| fields user, app, action}
The command that removes duplicates from your search results - CORRECT ANSWER dedup {| dedup VendorCity, VendorState}
The command that orders your results in + (default) ascending or - descending - CORRECT ANSWER sort {| sort country, -city, state}
The command that controls the number of returned results - CORRECT ANSWER limit {| limit=20}
The command that finds the most common values of a given field in the results set. By default returns the first 10 values and displays in table format - CORRECT ANSWER top {| top src_ip}
Host - CORRECT ANSWER Name, IP address, or name of the network from which the events originated
Source - CORRECT ANSWER Name of the file, stream or other data input
Display the client_ip, action and status for the last 4 hours - CORRECT ANSWER | table client_ip, action, status
rare {| rare src_ip} - CORRECT ANSWER The command that finds the least common values of a given field in the results set. By default returns the first 10 values and displays in table format
stats {| stats count} - CORRECT ANSWER The command that enables you to calculate statistics on data that matches your search criteria
| top limit=5 src_ip - CORRECT ANSWER Returns the top 5 values of src_ip
| top user Xweb_code limit=3 - CORRECT ANSWER Displays the top 3 common values for users and web cats browsed in the last 24hrs
| top xweb_cat by user limit 3 - CORRECT ANSWER Displays the top 3 common we categories browsed by each user
|| top user x_web cat limit=3 countfield="total Viewed" showperc=f - CORRECT ANSWER Displays the top 3 user/web categories browsed combinations. Renames the count field and show count, but not the percentage
| (invalid OR failed) | stats count as "Potential Issues" - CORRECT ANSWER Counts the invalid or failed login attempts as "Potential Issues"
| stats count(vendor_action) as ActionEvents, count as TotalEvents - CORRECT ANSWER Counts the number of events during the last 15 min that contain a vendor action field. Also count total events
by {| stats count by user, app, vendor_action} - CORRECT ANSWER The clause that, when used with the stats command, returns a count for each value of a named field or set of fields
distinct count(field) or dc(field) {| stats dc(s_hostname) as Websites} - CORRECT ANSWER Stats function that provides a count of how many unique values there are for a given field in the result set
sum(field) {| stats sum(sc_bytes) as Bandwidth by s_host} - CORRECT ANSWER Stats function that sums the actual values of a specific field
avg(field) {| stats avg(sc_bytes) as "average Bytes" by usage} - CORRECT ANSWER Stats function that provides the average numeric value for the given numeric field
list(field) {| stats list(s_hostname) as "Web Sites" by username} - CORRECT ANSWER Stats function that lists all field values for a given field
values(field) {| stats values(s_hostname) as "Web Sites" by username} - CORRECT ANSWER Stats function that returns a list of "unique" field values
Three main methods to create tables and visualizations in Splunk are: - CORRECT ANSWER 1) Select a field from the fields sidebar
2) Use the Pivot interface
3) Use a transforming command in the search bar
Consists of one or more panels displaying data visually - i.e. events, tables, or charts - CORRECT ANSWER Dashboard
(T/F) A report or a pivot cannot be used to create a panel on a dashboard - CORRECT ANSWER False
(T/F) Any change to the underlying dashboard will not affect every dashboard panel that utilizes that report - CORRECT ANSWER False
Used when static or unchanging data is required for searches but isn't available in the index - CORRECT ANSWER Lookups
This allows you to add more fields to your events and are usually defined in a static.csv file our outputted by a python script - CORRECT ANSWER Lookups
The command that loads results from a specified static lookup - CORRECT ANSWER inputlookup {| inputlookup products.csv}
[Show More]