Splunk Quiz

Splunk Quiz




1
Splunk flow is

  1. Index, Search, Add knowledge, Monitor/Alert, Report/Analyse
  2. Index, Add knowledge, search, Monitor/Alert, Report/Analyse
  3. Index, Add knowledge, search, Report/Analyse,Monitor/Alert,
  4. None of the above

Answer : Index, Search, Add knowledge, Monitor/Alert, Report/Analyse

 
2
Existing  License can be merged with another lincese

  1. FALSE
  2. TRUE

Answer : TRUE

 
3
Dashboard is portable

  1. TRUE
  2. FALSE

Answer : FALSE

 
4
Deployement server is used for

  1. Deploy the apps in splunk
  2. Deploy the apps in multiple apps in group of splunk server.
  3. distributing configurations, apps, and content updates in splunk server
  4. distributing configurations, apps, and content updates to groups of Splunk

Answer : distributing configurations, apps, and content updates to groups of Splunk

 
5
Splunk access can be merged with LDAP Dir

  1. TRUE
  2. FALSE

Answer : TRUE

 
6
Extracted field can be shared across the data sources

  1. TRUE
  2. FALSE

Answer : TRUE

 
7
Access Roles are

  1. ADMIN
  2. ADMIN, USERS
  3. ADMIN/POWER USERS/USERS
  4. ADMIN/POWER USERS

Answer : ADMIN/POWER USERS/USERS

 
8
POWER USERS role is

  1. This role has the most capabilities assigned to it.
  2. This role can edit all shared objects (saved searches, etc) and alerts, tag events, and other similar tasks.
  3. This role can create and edit its own saved searches, run searches, edit its own preferences, create and edit event types, and other similar tasks.
  4. All of the above

Answer : This role can edit all shared objects (saved searches, etc) and alerts, tag events, and other similar tasks.

 
9
Index file is not portable and specific to the installeled instance.

  1. TRUE
  2. FALSE

Answer : FALSE




10
Default index size is

  1. 50 MB
  2. 50 GB
  3. 500 MB
  4. 500 GB

Answer : 50 GB

 
11
Reguler expression to capture the specific name with in statement is

  1. “NAME”
  2. {NAME}
  3. [NAME]
  4. <NAME>

Answer : <NAME>

 
12
Splunk breaks up data into events and gives each a timestamp, host, source, and sourcetype automatically.

  1. TRUE
  2. FALSE

Answer : TRUE

 
13
Splunk search result can be saved as — format

  1. XML
  2. txt
  3. CSV
  4. JSON

Answer : XML,CSV,JSON

 
14
Event types can help you automatically identify events based on source data

  1. TRUE
  2. FALSE

Answer : FALSE

 
15
Alert can send

  1. Email
  2. Trigger script
  3. RSS Feed
  4. All of the above

Answer : All of the above

 
16
Transaction is any group of conceptually related events that span time

  1. TRUE
  2. FALSE

Answer : TRUE

 
17
Lookup is used for

  1. Allow to refer the external data
  2. Data not to indexed in splunk
  3. Add more fields in the results
  4. All of the above

Answer : Data not to indexed in splunk,Add more fields in the results

 
18
Lookup has capability of

  1. File based Lookup
  2. Table based lookup
  3. Script based look up
  4. None of the above

Answer : File based Lookup, Script based look up

 
19
Summary index used for

  1. Efficiently report on large volumes of data
  2. Build a rolling report that shows aggregated statistics over short period of time
  3. Searches or reports that may take several minutes or more to complete can be
  4. generated quickly
  5. All of the above

Answer : Efficiently report on large volumes of data, Searches or reports that may take several minutes or more to complete can be generated quickly




20
Backfill is used for

  1. Remove the duplicate data in source
  2. remove the duplicate in indexer
  3. Fill the Summary index
  4. Schdule the job

Answer : Fill the Summary index

 
21
What are forwarders

  1. Forwarders are small instances of Splunk that allow you to gather data and “forward” it to a central Splunk server or servers
  2. Sometimes they are the only way to get data from production to your index
  3. As we will also see they are also often the best way to gather data
  4. None of the above

Answer : Forwarders are small instances of Splunk that allow you to gather data and “forward” it to a central Splunk server or servers,Sometimes they are the only way to get data from production to your index,As we will also see they are also often the best way to gather data

 
22
“Heavy” forwarder is

  1. Full Splunk instance – does everything but write data to index
  2. Splunk Web can be used
  3. Breaks data into events before forwarding
  4. Can handle content-based routing

Answer : A,B,C,D

 
23
Forwarder can be managed using deployment server

  1. TRUE
  2. FALSE

Answer : TRUE

 
24
Default forwarder port is

  1. 8000
  2. 9997
  3. 9977
  4. 8001

Answer : 9997

 
25
How to create Search time field

  1. Edit config files
  2. Field Extractor
  3. rex command in the search language
  4. All of the above

Answer : All of the above

 
26
Data size and retention times are set on

  1. host based
  2. indexs based
  3. source based
  4. Soruce type based

Answer : indexs based

 
27
Cold, Frozen data available for searching

  1. TRUE
  2. FALSE

Answer : TRUE

 
28
_thefishbucket

  1. Splunk stores file information for its SOS function
  2. Splunk stores file information for its errorlog function
  3. Splunk stores file information for its alert function
  4. Splunk stores file information for its monitor function

Answer : Splunk stores file information for its monitor function

 
29
Multiple search heads can share only configuration data

  1. TRUE
  2. FALSE

Answer : FALSE

 
30
Splunk consumes it and
ignores all other files in the set

  1. Blacklisted
  2. whitelisted
  3. regex
  4. None of the above

Answer : whitelisted