Splunk Skills Assessment-Updated
Splunk Skills Assessment-Updated
the indexer and indexer cluster peer node run on which ports,
TCP/8000,
TCP 8089,
TCP/9887,
TCP9997
SEARCH HEADS,
INPUT,
FORWARDERS,
PARSING
what is the max daily indexing for splunk enterprise and cloud,
500MB,
20GB,
5TB,
UNLIMITED
After installing Splunk ,you would like to troubleshoot various default configurations. Select the option
that depicts an accurate use of the btool command to accomplish this task
You are tasked with performing a field extraction . What are some of the ways in which this action can
be performed?
Search Query
Regular Expression
\d +\s\w+\d+\s\d+:\d+:\d+
AA Aug 2017 18:45:20
You have installed Splunk.What is the best way to check the status of an existing installation
Distribute streaming
Transforming
Processing
Orchestrating
What are the options for saving the internal data type
Save as a Report
Save as a table
Save as an alert
Save as an event
Splunk Administrator
SIEM
IDS
IPS
Firewall
What are the recommended deployment scales for a very small office/department
10GB
20GB
50 FORWARDERS
100 FORWARDERS
What is Splunkbase
You are tasked with defining some actions based on the previous alert trigger conditions. What options
does Splunk provide for this?
Database Query
Send Email
Universal Forwarder sends Data to the Parsing/Indexing Engine and feeds results to the Search Heads
Universal Forwarder sends Data to the indexing Engine and Feeds results to the Search Heads
Universal File System sends Data to the Parsing/Indexing Engine and Feeds results to the Search Header
Universal Forwarder sends Data to the Ingest Engine and Feeds results to the Symbolic Header
Events
Schedules
Alerts
Birthdates
Select the option that allows you to perform a search using a lookup table
event-destfield]
Lookup [local=bool] [update=bool] lookup
event-destfield]
event-destfield]
Universal Forwarder
Distributes searches
Heavy Forwarder
When is it most appropriate to use a regular expression for field extraction?
Numerical Data
Structured Data
Unstructured Data
Alpha-numerical Data
Aggregates,simulates,fosters,helps
Aggregates,processes, analyzes,helps
Line breaks
Event logs
Date Entries
Select the function of indexers
Receive data
Search management
Scheduled searches
Index data
Continously runs and triggers alerts when there are more than 2 events
Continously runs and triggers alerts when there are more than 5 events
Runs a single time and triggers alerts when there are more than 5 events
Continously runs and triggers alerts when there are more than 5 events
Risk Behavior
Entity Profiling
Log Aggregation
Ad Hoc searches
Select the option that best describes the method(s) of configuring load balancing for Splunk
What are the conditions in which you would need to use quotation marks in Splunk?
Regular Expressions
Spaces
Horizontal scaling
Receive data
Search management
Scheduled searches
Index data
TCP/UDP ports
Syslog collection
APIs
Drivers
Log Aggregation
Network events
System Logs
Memory Fragments
Management/REST API
Structured
Binary
File
Unstructured