10 free sample questions from a bank of 273, with the correct answers and explanations. No signup required — start practising right now.
1Which one of the following statements about the search command is true?
It does not allow the use of wildcards.
It treats field values in a case-sensitive manner.
It can only be used at the beginning of the search pipeline.
It behaves exactly like search strings before the first pipe.
Answer: D
2Which of the following statements would help a user choose between the transaction and stats commands?
stats can only group events using IP addresses.
The transaction command is faster and more efficient.
There is a 1000 event limitation with the transaction command.
Use stats when the events need to be viewed as a single correlated event.
Answer: C
3What is the correct syntax to find events associated with a tag?
tag: =
tags=
tags: =
tag=
Answer: D
4Which of the following is true about the Splunk Common Information Model (CIM)?
The CIM contains 28 pre-configured datasets.
The data models included in the CIM are configured with data model acceleration turned on.
The data models included in the CIM are configured with data model acceleration turned off.
The CIM is an app that needs to run on the indexer.
Answer: C
5Consider the following search run over a time range of last 7 days:
index=web sourcetype=access_combined | timechart avg(bytes) by product_name
Which option is used to change the default time span so that results are grouped into 12 hour intervals?
timespan=12
span=12h
timespan=12h
span=12
Answer: B
6When would transaction be used instead of stats?
To have a faster and more efficient search.
To see results of a calculation.
To group events based on start/end values.
To group events based on a single field value.
Answer: C
7Given the following eval statement:
... | eval field1 = if(isnotnull(fieid1),field1,0), field2 = if(isnull
Which of the following is the equivalent using fillnull?