SPLK 1001 Questions
SPLK 1001 Questions
SPLK 1001 Questions
SPLK-1001 Exam
Splunk Core Certified User Exam
Version: 10.0
Question: 1
What is the correct syntax to count the number of events containing a vendor_action field?
Answer: C
Question: 2
By default, which of the following fields would be listed in the fields sidebar under interesting Fields?
A. host
B. index
C. source
D. sourcetype
Answer: A
Question: 3
When looking at a dashboard panel that is based on a report, which of the following is true?
A. You can modify the search string in the panel, and you can change and configure the visualization.
B. You can modify the search string in the panel, but you cannot change and configure the
visualization.
C. You cannot modify the search string in the panel, but you can change and configure the
visualization.
D. You cannot modify the search string in the panel, and you cannot change and configure the
visualization.
Answer: C
Question: 4
Answer: A
Question: 5
Answer: D
Question: 6
A. Dashboards
B. Metadata only
C. Non-interesting fields
D. Field descriptions
Answer: C
Question: 7
A. action+purchase
B. action=purchase
C. action | purchase
D. action equal purchase
Answer: B
Question: 8
Answer: D
Question: 9
A. Parentheses
B. @ or # symbols
C. Quotation marks
D. Relational operators such as =, <, or >
Answer: D
Question: 10
When a Splunk search generates calculated data that appears in the Statistics taB. in what formats
can the results be exported?
Answer: D
Question: 11
Answer: D
Question: 12
In a deployment with multiple indexes, what will happen when a search is run and an index is not
specified in the search string?
Answer: D