Splunk Quiz

Splunk Quiz




1
Splunk flow is

  1. Index, Search, Add knowledge, Monitor/Alert, Report/Analyse
  2. Index, Add knowledge, search, Monitor/Alert, Report/Analyse
  3. Index, Add knowledge, search, Report/Analyse,Monitor/Alert,
  4. None of the above

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : Index, Search, Add knowledge, Monitor/Alert, Report/Analyse[/bg_collapse]
 
2
Existing  License can be merged with another lincese

  1. FALSE
  2. TRUE

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : TRUE[/bg_collapse]
 
3
Dashboard is portable

  1. TRUE
  2. FALSE

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : FALSE[/bg_collapse]
 
4
Deployement server is used for

  1. Deploy the apps in splunk
  2. Deploy the apps in multiple apps in group of splunk server.
  3. distributing configurations, apps, and content updates in splunk server
  4. distributing configurations, apps, and content updates to groups of Splunk

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : distributing configurations, apps, and content updates to groups of Splunk [/bg_collapse]
 
5
Splunk access can be merged with LDAP Dir

  1. TRUE
  2. FALSE

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : TRUE[/bg_collapse]
 
6
Extracted field can be shared across the data sources

  1. TRUE
  2. FALSE

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : TRUE[/bg_collapse]
 
7
Access Roles are

  1. ADMIN
  2. ADMIN, USERS
  3. ADMIN/POWER USERS/USERS
  4. ADMIN/POWER USERS

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : ADMIN/POWER USERS/USERS[/bg_collapse]
 
8
POWER USERS role is

  1. This role has the most capabilities assigned to it.
  2. This role can edit all shared objects (saved searches, etc) and alerts, tag events, and other similar tasks.
  3. This role can create and edit its own saved searches, run searches, edit its own preferences, create and edit event types, and other similar tasks.
  4. All of the above

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : This role can edit all shared objects (saved searches, etc) and alerts, tag events, and other similar tasks. [/bg_collapse]
 
9
Index file is not portable and specific to the installeled instance.

  1. TRUE
  2. FALSE

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : FALSE[/bg_collapse]



10
Default index size is

  1. 50 MB
  2. 50 GB
  3. 500 MB
  4. 500 GB

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : 50 GB[/bg_collapse]
 
11
Reguler expression to capture the specific name with in statement is

  1. “NAME”
  2. {NAME}
  3. [NAME]
  4. <NAME>

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : <NAME>[/bg_collapse]
 
12
Splunk breaks up data into events and gives each a timestamp, host, source, and sourcetype automatically.

  1. TRUE
  2. FALSE

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : TRUE[/bg_collapse]
 
13
Splunk search result can be saved as — format

  1. XML
  2. txt
  3. CSV
  4. JSON

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : XML,CSV,JSON[/bg_collapse]
 
14
Event types can help you automatically identify events based on source data

  1. TRUE
  2. FALSE

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : FALSE[/bg_collapse]
 
15
Alert can send

  1. Email
  2. Trigger script
  3. RSS Feed
  4. All of the above

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : All of the above[/bg_collapse]
 
16
Transaction is any group of conceptually related events that span time

  1. TRUE
  2. FALSE

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : TRUE[/bg_collapse]
 
17
Lookup is used for

  1. Allow to refer the external data
  2. Data not to indexed in splunk
  3. Add more fields in the results
  4. All of the above

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : Data not to indexed in splunk,Add more fields in the results[/bg_collapse]
 
18
Lookup has capability of

  1. File based Lookup
  2. Table based lookup
  3. Script based look up
  4. None of the above

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : File based Lookup, Script based look up[/bg_collapse]
 
19
Summary index used for

  1. Efficiently report on large volumes of data
  2. Build a rolling report that shows aggregated statistics over short period of time
  3. Searches or reports that may take several minutes or more to complete can be
  4. generated quickly
  5. All of the above

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : Efficiently report on large volumes of data, Searches or reports that may take several minutes or more to complete can be generated quickly[/bg_collapse]



20
Backfill is used for

  1. Remove the duplicate data in source
  2. remove the duplicate in indexer
  3. Fill the Summary index
  4. Schdule the job

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : Fill the Summary index[/bg_collapse]
 
21
What are forwarders

  1. Forwarders are small instances of Splunk that allow you to gather data and “forward” it to a central Splunk server or servers
  2. Sometimes they are the only way to get data from production to your index
  3. As we will also see they are also often the best way to gather data
  4. None of the above

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : Forwarders are small instances of Splunk that allow you to gather data and “forward” it to a central Splunk server or servers,Sometimes they are the only way to get data from production to your index,As we will also see they are also often the best way to gather data[/bg_collapse]
 
22
“Heavy” forwarder is

  1. Full Splunk instance – does everything but write data to index
  2. Splunk Web can be used
  3. Breaks data into events before forwarding
  4. Can handle content-based routing

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : A,B,C,D[/bg_collapse]
 
23
Forwarder can be managed using deployment server

  1. TRUE
  2. FALSE

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : TRUE[/bg_collapse]
 
24
Default forwarder port is

  1. 8000
  2. 9997
  3. 9977
  4. 8001

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : 9997[/bg_collapse]
 
25
How to create Search time field

  1. Edit config files
  2. Field Extractor
  3. rex command in the search language
  4. All of the above

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : All of the above[/bg_collapse]
 
26
Data size and retention times are set on

  1. host based
  2. indexs based
  3. source based
  4. Soruce type based

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : indexs based[/bg_collapse]
 
27
Cold, Frozen data available for searching

  1. TRUE
  2. FALSE

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : TRUE[/bg_collapse]
 
28
_thefishbucket

  1. Splunk stores file information for its SOS function
  2. Splunk stores file information for its errorlog function
  3. Splunk stores file information for its alert function
  4. Splunk stores file information for its monitor function

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : Splunk stores file information for its monitor function[/bg_collapse]
 
29
Multiple search heads can share only configuration data

  1. TRUE
  2. FALSE

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : FALSE[/bg_collapse]
 
30
Splunk consumes it and
ignores all other files in the set

  1. Blacklisted
  2. whitelisted
  3. regex
  4. None of the above

[bg_collapse view=”button-green” color=”#FFF” icon=”arrow” expand_text=”Show Answer” collapse_text=”Hide Answer” ]Answer : whitelisted[/bg_collapse]