Splunk SPLK-1001 - Splunk Core Certified User
Which search will return only events containing the word “error†and display the results as a table that includes
the fields named action, src, and dest?
Which all time unit abbreviations can you include in Advanced time range picker? (Choose seven.)
You can view the search result in following format (Choose three.):
Field values are case sensitive.
The new data uploaded in Splunk are shown in ________________.
This is what Splunk uses to categorize the data that is being indexed.
Splunk users are assigned roles. Which of the following do roles determine?
When using the top command in the following search, which of the following will be true about the results?
index="main" sourcetype="access_*" action="purchase" | top 3 statusCode by user showperc=f countfield=status_code_count
Use this command to use lookup fields in a search and see the lookup fields in the field sidebar.
In automatic lookup definitions, the _____ fields are those that are not in the event data.
