Splunk extracts fields from event data at index time and at search time.
A. True
B. False
Splunk internal fields contains general information about events and starts from underscore i.e. _ .
A. True
B. False
Which component of Splunk is primarily responsible for saving data?
A. Search Head
B. Heavy Forwarder
C. Indexer
D. Universal Forwarder
It is mandatory for the lookup file to have this for an automatic lookup to work.
A.
Source type
B.
At least five columns
C.
Timestamp
D.
Input filed
Input filed
How can results from a specified static lookup file be displayed?
A. lookup command
B. inputlookup command
C. Settings > Lookups > Input
D. Settings > Lookups > Upload
Splunk Components:
Which of the following are responsible for parsing incoming data and storing data on disc?
A.
forwarders
B.
indexers
C.
search heads
indexers
Page 3 out of 41 Pages |
Previous |