Splunk Fundamental 3 Quiz Questions and Answers

Which of the following fields is stored with the events in the index?

Answer :
  • source

What does the stats command do?

Answer :
  • Calculates statistics on data that matches the search criteria.

How can another user gain access to a saved report?

Answer :
  • The owner of the report can edit permissions from the Edit dropdown.

Once an alert is created, you can no longer edit its defining search.

Answer :
  • False

Charts can be based on numbers, time, or location.

Answer :
  • True

What hardware attribute would you need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?

Answer :
  • CPUs

How do you remove missing forwarders from the Monitoring Console?

Answer :
  • By rebuilding the forwarder asset table

Which of the following are methods for adding inputs in Splunk? (Select all that apply)

Answer :
  • Editing inpits.conf
  • Splunk Web
  • CLI

Splunk divides a stream of data into individual events.

Answer :
  • True

Which setting in indexes.conf allows data retention to be controlled by time?

Answer :
  • frozenTimePeriodInSecs