Sign In
Home/Splunk/SPLK-1001/Free questions

SPLK-1001 — Free Practice Questions

10 free sample questions from a bank of 299, with the correct answers and explanations. No signup required — start practising right now.

1Which search string only returns events from hostWWW3?
  • host=*
  • host=WWW3
  • host=WWW*
  • Host=WWW3
Answer: B
2When editing a dashboard, which of the following are possible options? (Choose all that apply.)
  • Add an output.
  • Export a dashboard panel.
  • Modify the chart type displayed in a dashboard panel.
  • Drag a dashboard panel to a different location on the dashboard.
Answer: C
3Portal for Splunk apps can be accessed through www.splunkbase.com
  • False
  • True
Answer: B
4Splunk shows data in __________________.
  • ASCII Character order.
  • Reverse chronological order.
  • Alphanumeric order.
  • Chronological order.
Answer: B
5Which of the following can be used as wildcard search in Splunk?
  • =
  • >
  • !
  • *
Answer: D
6What result will you get with following search index=test sourcetype="The_Questionnaire_P*" ?
  • the_questionnaire _pedia
  • the_questionnaire pedia
  • the_questionnaire_pedia
  • the_questionnaire Pedia
Answer: C
7Prefix wildcards might cause performance issues.
  • False
  • True
Answer: B
8Machine data can be in structured and unstructured format.
  • False
  • True
Answer: B
9Field names are case sensitive.
  • True
  • False
Answer: A
10Splunk internal fields contains general information about events and starts from underscore i.e. _ .
  • True
  • False
Answer: A

Want the full bank of 299 questions for SPLK-1001? See all practice exams.