Advanced Power User

79 Questions | Total Attempts: 700

SettingsSettingsSettings
Please wait...
Advanced Power User

Fundamentals 3 course


Questions and Answers
  • 1. 
    The search "fail" "password" returns the same results as ______________.
    • A. 

      Fail AND password

    • B. 

      Fail OR password 

    • C. 

      Fail=password 

    • D. 

      Fail NOT password 

  • 2. 
    Which is the most efficient use of a wildcard character in Splunk? 
    • A. 

      Fail*

    • B. 

      *ail

    • C. 

      Fa*l

    • D. 

      F**l

  • 3. 
    Which of these terms take precedence in this search: (status=fail action=login) OR ((status=failed action=edit) AND ((role=power AND username=*) OR rfid=*)) 
    • A. 

      Role=power

    • B. 

      Action=login

    • C. 

      Rfid=*

    • D. 

      Status=failed

  • 4. 
    Which is a valid Splunk comparison operator? 
    • A. 

      !=

    • B. 

      <>

    • C. 

      ?

    • D. 

      ==

  • 5. 
    Regular expressions in Splunk are NOT case sensitive.
    • A. 

      True

    • B. 

      False

  • 6. 
    What is the default number of field values returned by the fieldsummary command? 
    • A. 

      250

    • B. 

      10

    • C. 

      100

    • D. 

      20

  • 7. 
    ________ functions such as count, max, and range are used when you want to summarize values from events into a single meaningful value. 
    • A. 

      Summary

    • B. 

      Boolean

    • C. 

      Additive

    • D. 

      Aggregate

  • 8. 
    The ________________ command aggregates statistics to your searched events as they are seen in time. 
    • A. 

      Fieldsummary

    • B. 

      Eventstats

    • C. 

      Stats

    • D. 

      Streamstats

  • 9. 
    If you wanted to generate summary statistics for the fields in your events, you would use the fieldsummary command. 
    • A. 

      True

    • B. 

      False

  • 10. 
    When executing the appendpipe command, Splunk runs the subpipeline before it runs the initial search. 
    • A. 

      True

    • B. 

      False

  • 11. 
    A Boolean operator that can be used within an eval command, but can't be used as a Splunk search term is ______________. 
    • A. 

      XOR

    • B. 

      NOT

    • C. 

      AND

    • D. 

      OR

  • 12. 
    This printf function uses which specifier to return 3 decimal places to the results.
    • A. 

      %.3

    • B. 

      %+3

    • C. 

      %%%

    • D. 

      %,3

  • 13. 
    Which of the following arguments can the tostring function take? 
    • A. 

      Duration

    • B. 

      Hex

    • C. 

      Eventcount

    • D. 

      Periods

  • 14. 
    The tonumber function can convert a binary value to a decimal by adding the optional base argument of "2" to the function. 
    • A. 

      True

    • B. 

      False

  • 15. 
    The tostring argument of _________ will format a field as a time value: 
    • A. 

      Hex

    • B. 

      Binary

    • C. 

      Commas

    • D. 

      Duration

  • 16. 
    What value is returned by the time function? 
    • A. 

      The time an event was processed by the eval command 

    • B. 

      The time an event was processed by the stats command 

    • C. 

      The time a search including a transforming command took to finish 

    • D. 

      The range of time containing returned events 

  • 17. 
    By using the relative_time() function of the eval command, we can return a value shifted forward or back in time relative to a specified time. 
    • A. 

      True

    • B. 

      False

  • 18. 
    If we wanted to display the time a search was started, we would use the __________ function of the eval command. 
    • A. 

      Start()

    • B. 

      Now()

    • C. 

      Begin()

    • D. 

      Time()

  • 19. 
    When is the relative_time function used? 
    • A. 

      To find the average time between events 

    • B. 

      When adding or subtracting time from a timestamp 

    • C. 

      To return a value of the time between recent searches 

    • D. 

      When defining the frequency of a scheduled report 

  • 20. 
    Which function of the eval command converts a UNIX timestamp into a string? 
    • A. 

      Converttime

    • B. 

      Strftime 

    • C. 

      Strptime 

    • D. 

      Stringtime 

  • 21. 
    What text function can be used with eval to substitute characters in field values?
    • A. 

      Replace

    • B. 

      Fieldreplace

    • C. 

      Substitute

    • D. 

      Charsub

  • 22. 
    What is the purpose of the substr function? 
    • A. 

      To push parts of a search into a subpipeline 

    • B. 

      To specify the order in which to run commands in a search string 

    • C. 

      To return only a part of string field values 

    • D. 

      To aid Splunk in parsing which part of a subsearch to pass to search heads 

  • 23. 
    Which commands can use all of the text functions available to eval? Select your answer.
    • A. 

      Fieldformat and where 

    • B. 

      Stats and where

    • C. 

      Fieldformat and search

    • D. 

      Search and where

  • 24. 
    The eval command substr("Dream Crusher", -7, 5) will result in a string of _____________. 
    • A. 

      Crush

    • B. 

      Am Crusher

    • C. 

      Dream C

    • D. 

      Rusher

  • 25. 
    Given a field-value pair of Department="Sales", ...| eval Department=upper(Department), will result in a new field-value pair of Department="SALES". 
    • A. 

      True

    • B. 

      False

Back to Top Back to top