What is a suggested Splunk best practice for naming reports?
A.
Reports are best named using many numbers so they can be more easily sorted.
B.
Use a consistent naming convention so they are easily separated by characteristics such as group and object.
C.
Name reports as uniquely as possible with no overlap to differentiate them from one another.
D.
Any naming convention is fine as long as you keep an external spreadsheet to keep track.
Name reports as uniquely as possible with no overlap to differentiate them from one another.
What does the following specified time range do?
earliest=-72h@h latest=@d
A.
Look back 3 days ago and prior
B.
Look back 72 hours up to one day ago
C.
Look back 72 hours, up to the end of today
D.
Look back from 3 days ago up to the beginning of today
Look back 72 hours up to one day ago
Which of the following is true about user account settings and preferences?
A.
Search & Reporting is the only app that can be set as the default application.
B.
Full names can only be changed by accounts with a Power User or Admin role.
C.
Time zones are automatically updated based on the setting of the computer accessing Splunk.
D.
Full name, time zone, and default app can be defined by clicking the login name in the Splunk bar.
Full names can only be changed by accounts with a Power User or Admin role.
Which of the following are common constraints of the top command?
A.
limit, count
B.
limit, showpercent
C.
limits, countfield
D.
showperc, countfield
limit, count
What is the purpose of using a by clause with the stats command?
A.
To group the results by one or more fields.
B.
To compute numerical statistics on each field.
C.
To specify how the values in a list are delimited.
D.
To partition the input data based on the split-by fields
To group the results by one or more fields.
Page 5 out of 23 Pages |
Previous |