In a deployment with multiple indexes, what will happen when a search is run and an index is not specified in the search string?
A. No events will be returned.
B. Splunk will prompt you to specify an index.
C. All non-indexed events to which the user has access will be returned.
D. Events from every index searched by default to which the user has access will be returned.
Which of the following are not true about lookups? (Select all that apply.)
A. Lookups can be time based
B. Search results can be used to populate a lookup table
C. Splunk DB Connect can be used to populate a lookup table from relational databases
D. Output from a script can be used to populate a lookup table
E. Lookup have a 10mg maximum size limit
Which of the following fields is stored with the events in the index?
A. user
B. source
C. location
D. sourcelp
Forward Option gather and forward data to indexers over a receiving port from remote machines.
A. False
B. True
Assuming a user has the capability to edit reports, which of the following are editable?
A. Acceleration, schedule, permissions
B. The report's name, schedule, permissions
C. The report's name, acceleration, schedule
D. The report's name, acceleration, permissions
What does the rare command do?
A. Returns the least common field values of a given field in the results.
B. Returns the most common field values of a given field in the results.
C. Returns the top 10 field values of a given field in the results.
D. Returns the lowest 10 field values of a given field in the results.
By default search results are not returned in ________ order.
A. Chronological
B. Reverser chronological
C. ASCIE
D. Alphabetical
How many minutes, by default, is the time to live (ttl) for an ad-hoc search job?
A. 5 minutes
B. 1 minute
C. 10 minutes
D. 60 minutes
This clause is used to group the output of a stats command by a specific name.
A. Rex
B. As
C. List D. By