Which Field/Value pair will return only events found in the index named security?
B
Explanation:
Reference:
https://answers.splunk.com/answers/712164/why-are-the-wineventlogssecurity-indexing-indiffe.html
Which statement describes field discovery at search time?
D
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.2/Search/Changethesearchmode
What are the three main Splunk components?
B
Explanation:
Reference:
https://www.edureka.co/blog/splunk-architecture/
When is an alert triggered?
D
Explanation:
Reference:
https://books.google.com.pk/books?id=sNwkBQAAQBAJ&pg=PT525&lpg=PT525&dq=splunk+alert
+triggered+When+results+of+a+search+meet+a+specifically+defined
+condition&source=bl&ots=avtEx5luxo&sig=ACfU3U1ZVob_j9nU243Te2vhqwxI3YvJuA&hl=en&sa=X
&ved=2a
hUKEwjm48rmkfXoAhUlMewKHb_FAbkQ6AEwB3oECBYQJg
QUESTION 197
Which search will return the 15 least common field values for the dest_ip field?
C
Explanation:
Reference:
https://answers.splunk.com/answers/41928/add-a-lookup-csv-colum-information-to-the-results-ofa-inputlookup-search.html
What is the default lifetime of every Splunk search job?
D
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.3/Search/Extendjoblifetimes
In the Fields sidebar, what does the number directly to the right of the field name indicate?
C
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.3/SearchTutorial/Usefieldstosearch
How can results from a specified static lookup file be displayed?
B
When is the pipe character, I, used in search strings?
B
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.3/Search/
Aboutsearchlanguagesyntax#Quotes_and_escaping_characters
Which of the following is the best way to create a report that shows the last 24 hours of events?
D
What are the two most efficient search filters?
B
Which of the following is a metadata field assigned to every event in Splunk?
A
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Assignmetadatatoeventsdynamically
Assuming a user has the capability to edit reports, which of the following are editable?
B
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.3/Report/Createandeditreports
What is a quick, comprehensive way to learn what data is present in a Splunk deployment?
C
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.3/InheritedDeployment/Yourdata
When viewing results of a search job from the Activity menu, which of the following is displayed?
C