Splunk SPLK-1001 - Splunk Core Certified User
Field names are case sensitive.
What is the default lifetime of every Splunk search job?
After running a search, what effect does clicking and dragging across the timeline have?
What is the purpose of using a by clause with the stats command?
What can be included in the All Fields option in the sidebar?
Fields are searchable key value pairs in your event data.
Which of the following reports is available in the Fields window?
Which search string matches only events with the status_code of 4:4?
When saving a search directly to a dashboard panel instead of saving as a report first, which of the following is
created?
What is the result of the following search?
index=myindex source=c: \mydata. txt NOT error=*
