Splunk Core Certified User (SPLK-1001) Free Practice Test
Question 1
Which of the following is a correct way to limit search results to display the 5 most common values of a field?
Correct Answer: C
Question 2
In monitor option you can select the following options in GUI.
Correct Answer: C
Question 3
Log filtering/parsing can be done from _____________.
Correct Answer: D
Question 4
At the time of searching the start time is 03:35:08.
Will it look back to 03:00:00 if we use -30m@h in searching?
Will it look back to 03:00:00 if we use -30m@h in searching?
Correct Answer: B
Question 5
Search Assistant is enabled by default in the SPL editor with compact settings.
Correct Answer: B
Question 6
Portal for Splunk apps can be accessed through www.splunkbase.com
Correct Answer: B
Question 7
In a deployment with multiple indexes, what will happen when a search is run and an index is not specified in the search string?
Correct Answer: D
Question 8
How do you add or remove fields from search results?
Correct Answer: B
Question 9
Which search will return only events containing the word "error" and display the results as a table that includes the fields named action, src, and dest?
Correct Answer: A
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 10
What kind of logs can Splunk Index?
Correct Answer: B
Question 11
Which symbol is used to snap the time?
Correct Answer: D
Question 12
Which of the following statements describes a search job?
Correct Answer: B
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 13
By default, all users have DELETE permission to ALL knowledge objects.
Correct Answer: A
Question 14
Assuming a user has the capability to edit reports, which of the following are editable?
Correct Answer: A
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).