Splunk Core Certified User SPLK-1001 Exam Questions
Question #1 (Topic: Demo Questions)
Splunk extracts fields from event data at index time and at search time.
Correct Answer: A
Explanation:
[Reference: https://docs.splunk.com/Documentation/Splunk/7.2.3/SearchTutorial/Usefieldstosearch, , ]
[Reference: https://docs.splunk.com/Documentation/Splunk/7.2.3/SearchTutorial/Usefieldstosearch, , ]
Question #2 (Topic: Demo Questions)
Which search will return the 15 least common field values for the dest_ip field?
Correct Answer: C
Explanation:
[Reference: https://answers.splunk.com/answers/41928/add-a-lookup-csv-colum-information-to-the-results-ofa-inputlookup-search.html, ]
Question #3 (Topic: Demo Questions)
Which of the statements are correct? (Choose three.)
Correct Answer: A, C, E
Question #4 (Topic: Demo Questions)
What determines the scope of data that appears in a scheduled report?
Correct Answer: D
Question #5 (Topic: Demo Questions)
What is Splunk?