Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-1001 Practice Exam with Questions & Answers | Set: 2

Questions 11

What can be configured using the Edit Job Settings menu?

Options:
A.

Export the results to CSV format

B.

Add the Job results to a dashboard

C.

Schedule the Job to re-run in 10 minutes

D.

Change Job Lifetime from 10 minutes to 7 days.

Splunk SPLK-1001 Premium Access
Questions 12

Query - status != 100:

Options:
A.

Will return event where status field exist but value of that field is not 100.

B.

Will return event where status field exist but value of that field is not 100 and all events where status field

doesn't exist.

C.

Will get different results depending on data

Questions 13

Splunk Components:

Which of the following are responsible for reducing search results?

Options:
A.

search heads

B.

indexers

C.

forwarders

Questions 14

Which of the following searches would return only events that match the following criteria?

• Events are inside the main index

• The field status exists in the event

• The value in the status field does not equal 200

Options:
A.

index==main status!==200

B.

index=main NOT status=200

C.

index==main NOT status==200

D.

index-main status!=200

Questions 15

Which component of Splunk is primarily responsible for saving data?

Options:
A.

Search Head

B.

Heavy Forwarder

C.

Indexer

D.

Universal Forwarder

Questions 16

What is a quick, comprehensive way to learn what data is present in a Splunk deployment?

Options:
A.

Review Splunk reports

B.

Run ./splunk show

C.

Click Data Summary in Splunk Web

D.

Search index=* sourcetype=* host=*

Questions 17

What are the three main Splunk components?

Options:
A.

Search head, GPU, streamer

B.

Search head, indexer, forwarder

C.

Search head, SQL database, forwarder

D.

Search head, SSD, heavy weight agent

Questions 18

What is the correct syntax to count the number of events containing a vendor_action field?

Options:
A.

count stats vendor_action

B.

count stats (vendor_action)

C.

stats count (vendor_action)

D.

stats vendor_action (count)

Questions 19

What syntax is used to link key/value pairs in search strings?

Options:
A.

Parentheses

B.

@ or # symbols

C.

Quotation marks

D.

Relational operators such as =, <, or >

Questions 20

Splunk Parses data into individual events, extracts time, and assigns metadata.

Options:
A.

False

B.

True

Exam Code: SPLK-1001
Certification Provider: Splunk
Exam Name: Splunk Core Certified User
Last Update: Jul 19, 2025
Questions: 244