Splunk Fundamentals 2 Quiz Questions and Answers

Which of the following fields is stored with the events in the index?

Answer :
  • source

What does the stats command do?

Answer :
  • Calculates statistics on data that matches the search criteria.

How can another user gain access to a saved report?

Answer :
  • The owner of the report can edit permissions from the Edit dropdown.

Once an alert is created, you can no longer edit its defining search.

Answer :
  • False

Charts can be based on numbers, time, or location.

Answer :
  • True

The time stamp you see in the events is based on the time zone in your user account.

Answer :
  • True

What is the primary use for the rare command?

Answer :
  • To find the least common values of a field in a dataset.

Which command removes results with duplicate field values?

Answer :
  • dedup

True/False: Pivots can be saved as dashboards panels.

Answer :
  • True

Splunk must index data before being able to search through massive amounts of data.

Answer :
  • True