Which are the boolean operators that can be used by the eval command? select all that apply.
Use the eval command to calculate the value of an expression and display the value in a new field. Show
For examples of using this command in typical scenarios, see:
Following are some examples of the eval command. *|eval newField = 'foo'*|eval newField = 123*|eval newField = upper(Target)*|eval newField = length('hello world')*|eval newField = replace('aabbcc', 'bb', 'xx')*|eval newField = concat(host, concat (':', port))*|eval newField = host || ':'|| port*|eval newField = url('Destination URL')*|eval newField = substr('aabbcc', 2, 4)*|eval newField = round(123.4)*|eval newField = unit('Content Size', KB)eval 'File Size (bytes)' = unit('File Size', 'byte') eval 'File Size (KB)' = unit('File Size'/1024, 'kb')eval 'File Size (MB)' = unit('File Size'/(1024*1024), 'mb')eval 'Time Taken (Sec)' = unit('Time Taken (ms)'/1000, 'SEC')*|eval newField = floor(4096/1024)+Length*|eval newField = if (max(Length)(Target), length(Severity)) <= 20, 'OK', 'ERROR')*|eval newField = urldecode('http%3A%2F%2Fexample.com%3A893%2Fsolr%2FCORE_0_0%2Fquery')*|eval newField = 'Host Name (Destination)' in (host1, host2)The following example compares the IP addresses in the field srvrhostip to a subnet range. *|eval newField = if (cidrmatch(srvrhostip, '192.0.2.254/25') = 1, 'local', 'not local')The following example returns the string “Target”. *|eval newField = literal(Target)The following example removes the spaces and tabs from both the ends. *|eval newField = trim(Label)The following example removes the matching character from both the ends. *|eval newField = trim('User Name',h)The following example removes the matching character from the left end. *|eval newField = ltrim('Error ID',0)The following example removes the matching character from the right end. *|eval newField = rtrim('OS Process ID',2)The following example sets the field date to Start Date and defines the format of the date as MM/dd/yyyy HH:mm. *|eval date = toDate('Start Date', 'MM/dd/yyyy HH:mm')The following example sets the value of the field duration to 1.30. *|eval duration = toduration("1.30")The following example sets the value of the field duration to a numerical value which is the difference of End Time and Start Time. *|eval duration = formatDuration('End Time' - 'Start Time')The following examples illustrate the use of date functions. *| eval lastHour = dateAdd(now(), hour, -1) *| eval midnight = dateSet(now(), hour, 0, minute, 0, sec, 0, msec, 0) *| eval timeOnly = formatDate(now(), 'HH:mm:ss') *| eval now = now()The following example sets the value of the field newField with the position of .com in the uri string. *|eval newField = indexOf(uri, '.com')You can use the md5, sha1, and sha256 hash functions with the eval command to filter log data. The following example sets the value of the field user with the value sha1("jane"). *|eval user = sha1("jane")A field with a size or duration type unit would be used to format the values in the Link Analyze chart, addfields histograms and the Link Table: 'Log Source' = 'FMW WebLogic Server Access Logs' | link span = 5minute Time, Server | stats avg('Duration') as 'Raw Avg. Duration' avg('Content Size') as 'Raw Avg. Transfer Size' | eval 'Average Duration' = unit('Raw Avg. Duration', ms) | eval 'Average Transfer Size' = unit('Raw Avg. Transfer Size', byte) | classify 'Start Time', 'Average Duration', 'Average Transfer Size' as 'Response Time vs. Download Sizes'Mark a field as containing US Dollars, thousands of US Dollars, millions of US Dollars, or billions of US Dollars, respectively: | eval 'Amount in USD' = unit('Sales Price', usd) | eval 'Amount in Thousands (USD)' = usd('Quarterly Sales', usd_thousand) | eval 'Amount in Millions (USD)' = usd('Annual Profit', usd_million) | eval 'Amount in Billions (USD)' = usd('Annual Sales', usd_billion)
Are Boolean operators case sensitive?yesAre field names case sensitive?yesUsing a ____ ____ in Splunk is a way to search through text to find pattern matches in your data.Are they case sensitive?regular expressionyesTrue or False. Field values from lookup, tags, and field values with "eval" and "where" commands are not case sensitive.False. They are case sensitive.Are command names (i.e. stats, STATS), command clauses (i.e. "as," "by," "with), statistical functions (i.e. avg, AVG, Avg), search terms (i.e. failed, FAILED) and field values (i.e. host=www1, host=WWW1) case sensitive or case insensitive?case insensitiveAs events age in Splunk, they move from the ____ bucket, to the ____ bucket and finally to the ____ bucket.hot, warm, cold
Who can configure settings and add more to buckets? Users, admins or power users?adminsWhat is the most efficient filter to use when searching events? After time, the most powerful fields to filter are what?timeindex, host, source and sourcetypeWhat command would you use in order to only extract (discover) the fields you need?fields command____ mode in Splunk = performance over completeness.____ mode in Splunk balances speed and completeness.____ mode in Splunk focuses on completeness over performancefastsmartverboseRemoving duplicates then sorting is ____ (faster or slower) than sorting then removing duplicates?faster____ commands massage raw data in tables and transform specified cell values for each event into numerical values that you can use for statistical purposes.transformingWhat commands are required to 'transform' search results into visualizations?transformingWhat type of commands are the following?toprarecharttimechartstatsgeostatstransformingIn fast mode, verbose mode, and smart mode what is not available for non-transforming searches?statistics and visualizationsOnly metadata fields (host, source and sourcetype) and fields specified in a search are available in ___ mode.fastIn fast mode transforming searches, ____ and ___ are not available. However, statistics and visualizations are.events, patternsIn ___ mode, events and patterns are available in non-transforming searches, but statistics and visualizations are not.Are events, patterns, statistics and visualizations available for transforming searches?verboseyesIn smart mode, events and patterns are NOT available. However ____ and ____ are.statistics and visualizationsWhat tool allows you to examine the:Overall stats of search (e.g., records processed and returned, processing time)How search was processed Where Splunk spent its timeSearch Job Inspector toolWhat is used to troubleshoot a search’s performance and understand the impact of knowledge objects on processing (e.g., event types, tags, lookups)?Search Job Inspector toolHeader, execution costs and search job properties are the 3 ____ of what tool?componentsSearch Job Inspector toolWhich component of the Search Job Inspector tool provides basic information, including time to run and # of events scanned?headerWhich component of the Search Job Inspector tool provides details on the cost to retrieve results?execution costscommand.search.index, command.search.filter, and command.search.rawdata are all ____ ___ shown in the Search Job Inspector tool.execution costsWhich execution cost of the Search Job Inspector tool specifies the time that it took to filter out events that did not match?a. command.search.rawdatab. command.search.indexc. command.search.filterc. command.search.filterWhich execution cost of the Search Job Inspector tool specifies the time that it took to search the index for the location to read in rawdata files?a. command.search.rawdatab. command.search.indexc. command.search.filterb. command.search.indexWhich execution cost of the Search Job Inspector tool specifies the time that it took to read events from the rawdata files?a. command.search.rawdatab. command.search.indexc. command.search.filtera. command.search.rawdataAs events are stored by time, ______ is the most efficient filter.a. _timeb. _rawc. _introspectiona. _timeSelect all that are considered case sensitive.a. Boolean operatorsb. tagsc. keywordsd. command functionsa. Boolean operatorsb. tagsThe Search Job Inspector has three components. Select all that apply.a. Headerb. Health checkc. Search job propertiesd. Execution costsa. Headerc. Search job propertiesd. Execution costsFor general search best practices, only use________ wildcards to make efficient use of index.a. trailingb. beginningc. middle-of-stringa. trailingWhen a search returns statistical values, results can be viewed in a table on the ___ tab or as a ____.statisticsvisualizationLines, column charts, pie charts, single values, gauges, maps and many more are all examples of what?visualizationsA ___ ____ is a sequence of related data points that are plotted in a visualization. They can generate various statistical or visualization results.data seriesMost visualizations require a ____ ___ table. A ___ ___ table consists of search results structured as a table with at least two columns.single seriesThe leftmost column of a single series table provides x-axis values or y-axis values? What axis are subsequent columns on?x-axis valuesthe y-axisTo get ___ ____ tables, you need to set up the underlying search with transforming commands such as "chart" and "timechart."multi-series tables___ ___ tables display statistical trends over time. They can be single-series or multi-series.time seriesWhat command do you have to use for a time series result?timechart commandWhat type of chart shows trends in the relationships between discrete data values?scatter charts____ charts show discrete values that do not occur at regular intervals or belong to a series.scatter
The ____ command can display any data series plotted across one or two dimensions.chartWhat chart command function is being used in the following search strings? (Note: The difference between the two are the "over" clause and the "by" clause in the second lines).index=security sourcetype=linux_secure| chart count over vendor_actionindex=security sourcetype=linux_secure| chart count by vendor_actioncount functionWhen you use the ___ function in Splunk, a table is created with a column that tallies the number of events for each value in the result set.countWith the ____ command, you can use the "by" clause with the "over" clause to split results (ie. over vendor_action by user). Or you can just use two "by" clauses (i.e. by vendor_action, user).chartYou can only split chart results over a maximumof how many dimensions using the chart command?twoChart and timechart commands automatically filter results to include the ____ highest values. Surplus values are grouped in "OTHER." Results can be skewed by "NULL" and "OTHER."a. fiveb. tenc. twentyd. fifteenb. tenWhat chart and timechart command values are shown by default?NULL and OTHER"useother=f" and "usenull=f" can be used to remove empty ____ and ____ values from display in a visualization using the chart command.NULL and OTHERWhat can be used to adjust the default number of plotted series (10) when using the chart command?limit argumentThe ____ command performs statistical aggregations against time. It also plots and trends data over time.timechart command"_time" using the timechart command is always on the x-axis or y-axis?
x-axisLine or area charts are the best representation of what type of chart?timechartsWith the timechart command,the default time intervals (or time ranges of a search) that can be used are span=1m which equals _____ minutes and span=30m which equals ____ hours.60 minutes24 hoursYou can adjust the time interval of a timechart by using what argument?"span" argumentThe ____ layout allows you to display multiple charts based on one result set and allows visual comparison between different categories.trellis layoutWhich command displays the output of the timechart command, so that each time period is a separate series?a. timechart commandb. chart commandc. timewrap commandc. timewrap commandWhich command can compare data over a specific time period, such as day-over-day or month-over-month?a. timechart commandb. timewrap commandc. chart commandb. timewrap commandWhat command is being used here?index=security sourcetype=linux_secure| stats count by src_ip, user, vendor_action, appstats commandWhat clause would you use to calculate statistics for two or more non time-based fields?"by" clauseTo get multi-series tables, you need to set up the underlying search with transforming commands. Select all that apply.a. chartb. abstractc. timecharta. chartc. timechartWhen using the timechart command, what option is used to specify the _time interval?a. groupb. trendc. spanc. spanWhich of the three transforming commands below allows you to split results over a maximum of TWO dimensions?a. statsb. chartc. timechartb. chartWhich of the three transforming commands below allows you to split results over a maximum of ONE dimension?a. statsb. chartc. timechartc. timechartWhich of the three transforming commands below allows you to split results over MANY dimensions?a. statsb. chartc. timecharta. statsWhich of the three transforming commands below does not allow you to limit the number of series shown, filter "other" and "null" series, and set value groups along the x-axis?a. statsb. chartc. timecharta. statsWhich transforming commands allow you to use "span" in order to set value groups along the x-axis?a. statsb. chartc. timechartb. chartc. timechartWhich commands would you use to count the frequency of a field(s)?a. statsb. chartc. top/rared. timechartc. top/rareWhich command is non time-based and would be used to calculate statistics for two or more "by" fields?a. statsb. chartc. top/rared. timecharta. statsWhich command is used to calculate statistics using an arbitrary field as the x-axis? This command also allows you to use "over" or "by" to specify the x-axis, and WILL NOT allow you to use "_time" on the x-axis.a. statsb. chartc. top/rared. timechartb. chartYou would use the ____ command to calculatestatistics with "_time" as the x-axis.a. statsb. chartc. top/rared. timechartd. timechartIf a "by" field is used for the timechart command, the output is a ____.tableTo get multi-series tables, you need to set up the underlying search with transforming commands. Select all that apply.a. chartb. abstractc. timecharta. chartc. timechartWhen using the timechart command, what option is used to specify the _time interval?a. groupb. trendc. spanc. span____ are aliases to field values. For example, if two host names refer to the same computer, you could give both host values the same ___ (for example, hal9000). When you search for ___=hal9000, Splunk returns events involving both host name values.Note: Answers for all blanks are the sametagstop, stats, chart, and timechart are all what type of commands?a. Sorting Results b. Filtering Results c. Grouping Results d. Reporting Resultse. Filtering, Modifying, and Adding Fieldsd. Reporting ResultsWhich transforming command returns the most frequently occurring typle of field values, along with their count and percent?a. statsb. chartc. topd. raree. timechartc. topThis command computes the moving averages of a field.trendline
There are 3 ____ that must be included when using the trendline command. ____ (acronym for simple moving average), _____ (acronym for exponential moving average), and ____ (acronym for weighted moving average).trendtypessmaemawmaThe ___ over which to compute a trend (which can be between whole numbers of 2 and 10,000) must be included when using the trend line command.periodWhen displaying data on maps, there are two types that can be used:A ____ map (which shades areas based on metrics).A ____ map (which displays statistical grouping based on geo location).ChoroplethClusterWhich command is used to look up and add location information to an event (including city, country, region, latitude and longitude)?a. geostatsb. iplocationc. statsd. charte. timechartb. iplocationTrue or False. The iplocation command DOES NOT automatically define default lat and lon fields required by geostats.FalseThe iplocation command AUTOMATICALLY defines default lat and lon fields required by geostats.The ____ command is used to compute statistical functions and render a cluster map. Data must include latitude and longitude values.a. chartb. iplocationc. statsd. geostatse. timechartd. geostatsWhen using the geostats command, you can control the column count, using the ______ argument.globallimit____ maps use shading to show relative metrics, such as sales, network intruders, etc. for predefined geographic regions.ChoroplethTo define regional boundaries for a choropleth map, you must have what type of files? Select all that apply.a. CSVb. KML (Keyhole Markup Language)c. JSONd. KMZ (compressed Keyhole Markup Language)e. XMLb. KML (Keyhole Markup Language)d. KMZ (compressed Keyhole Markup Language)The standard geo searches that Splunk ships with for the choropleth maps is:1. geo_us_states (which for what country?)2. geo_countries (which is for ____)and…| geom [featureCollection] [featureIdField=string](Note: No answer needed for this one)United Statescountries of the worldWith gauge visualizations, you can make adjustments to color by using UI or the ____ command.gauge____ layout displays multiple gauges when using a by clause in the stats command.trellisWith the timechart command, you can add a _____ and a trend. A ____ is an inline chart and is designed to display time-based trends associated with the primary key.(Note: Same answer for both)sparklineThe ____ command is used to compute the sum of all or selected columns, and place the total in the last row and last column.a. topb. statsc. chartd. addtotalse. timechartf. iplocationg. geostatsd. addtotalsWhen using the add totals command, ___=t counts the fields in each row under a column named, while ____=t counts the fields in each row in a row named.row=tcolumn=tThe trendline command provides three trend types. Select all that apply.a. tma (time)b. sma (simple)c. ema (exponential)d. wma (weighted)b. sma (simple)c. ema (exponential)d. wma (weighted)By default, the iplocation command adds fields to the results. Select all that apply.a. Cityb. lonc. pidd. Regionb. lonWhen using the addtotals command, the labelfield argument is valid only when _______.a. col=trueb. row=truec. fieldname=fa. col=trueThis command calculates an expression and puts the resulting value into a new field. For instance if a user creates the following search string:… | eval velocity=distance/timeThe resulting table would have the value for distance in one column, the value for time in another column and the eval velocity column would be the result of the # for distance divided by the number for time.eval commandWhen using the eval command, expressions must be separated by what character?a. >= b. ,c. !=b. ,The ____ command allows you to:Calculate expressionsPlace the results in a fieldUse that field in searches or other expressionsevalWhen using the eval command, the ____ function sets the value of a field to the number of decimals you specify. (ie. one number after the decimal, two numbers after the decimal, etc.)roundWhich type of eval command is represented by the following operators?+ - * / %a. Booleanb. Comparisonc. Arithmeticd. ConcatenationArithmeticWhich type of eval command is represented by the following operators?NOT AND OR XORa. Booleanb. Comparisonc. Arithmeticd. Concatenationa. BooleanWhich type of eval command is represented by the following operators?< > <= >= != = LIKEa. Booleanb. Comparisonc. Arithmeticd. Concatenationb. ComparisonWhich type of eval command is represented by the following operators?+ .a. Booleanb. Comparisonc. Arithmeticd. Concatenationd. ConcatenationWhen using the eval command, and the round function for results, If the number of decimals is unspecified, what is the result?a whole numberWhen using the eval command, the ____ function converts a numeric field value to a string.tostringWhen using the eval command and tostring function, there are 3 options that you can use to format the numbers in the table that is created:a. _____ which apply commas to the numbersb. _____ which format the numbers as hh:mm:ssc. _____ which formats the number in a hexadecimalPlace the following terms in the correct blank:"duration," "commas," "hex"a. commasb. durationc. hexWhich eval command function is described below?1. takes three arguments2. the first argument, X, is a boolean expression3. if argument X evaluates to TRUE, the result evaluates to the second argument, Y4. if argument X evaluates to FALSE, the result evaluates to the third argument, Z
"if" functionWhen using the eval command "if" function, non numeric values must be enclosed in _______.Are field values case sensitive when using this function, or case insensitive?double quotescase sensitiveThe eval command ____ function works similar to that of the "if" function. However, rather than the first argument being X, it's X1. The following arguments are Y1, X2, Y2, etc.Also, if none of the boolean expressions are true, the result evaluates to NULL.caseIf none of the boolean expressions were true using the eval command "case" function, what would the result be?NULLIdentify the functions used in both search strings:Search string #1:index=network sourcetype=cisco_wsa_squid| eval Risk = case(x_wbrs_score >= 5,"1 Very Safe",x_wbrs_score >= 3,"2 Safe",x_wbrs_score >= 0,"3 Neutral",x_wbrs_score >= -5,"4 Dangerous",x_wbrs_score < -5, "5 Very Dangerous")Search string #2index=sales sourcetype=vendor_sales| eval SalesTerritory =if ((VendorID >= 7000 AND VendorID < 8000), "Asia", "Rest of the World")1. case function2. if functionThe _____ command calculates an expression and puts the resulting value into a search results field.evalUnlike the eval "command" (which calculates an expression and puts the resulting value into a search results field), the eval "____" counts the number of events that have a specific field value.What function must be used along with the eval "____"?Note: Same answers for the blank spaces.functioncountTrue or False. Field values ARE case sensitive when using the eval "FUNCTION."TrueWhich command is described below? The "search" command, or the "where" command?1. Can be used at any point in the search pipeline2. Allows searching on keywords3. Treats field values in a "case insensitive" mannersearchIs the "search" command, or the "where" command being described below?1. Functions are available, such as isnotnull()2. Can’t appear before first pipe in search pipeline3. Can’t filter with keywords3. Treats field values in a "case-sensitive" manner4. Can compare values from two different fieldswhereWhich command is used here? Also describe what is happening?source=job_listings | where salary > industry_average"where" commandretrieves jobs listings and discards those whose salary is not greater than the industry averageWhen using the "like" operator with the "where" command, you must use (_) for __ character and(%) for _____ characters.Note: The blank spaces should be filled with quantities (i.e. one, a couple, multiple)one multipleWhat where command operator is being used in the following search string?index=security sourcetype=linux_secure| where like (user,"adm%")| dedup user| table userlikeWhen using the "where" command, use _____ to find events with an empty value for a specific field, and ____ to find events that contain a non-empty value for a particular field. On the other hand, _____ should be used to replace null values in fields. a. fillnullb. isnullc. isnotnullb. isnullc. isnotnulla. fillnullCreate a new field called velocity in each event. Calculate the velocity by dividing the values in the distance field by the values in the time field.a. |eval {velocity} = Value, distance OVER timeb. |eval velocity=distance/timec. |eval velocity=split(distance,time)b. |eval velocity=distance/timeIf you use the following eval command with the round() function, select a possible result:|eval bandwidth = round(Bytes/pow(1024,2), 2)a. 28b. 124.032c. 273.02c. 273.02The eval command supports comparison and conditional functions. Select all that apply.a. case (X1,"Y1",X2,"Y2",…)b. if (X,Y,Z)c. like (TEXT,PATTERN)d. tostring(X,Y)a. case (X1,"Y1",X2,"Y2",…)b. if (X,Y,Z)If you want to use the fillnull command and show a specific text, which syntax would be correct?a. | fillnull value="nada"b. | fillnull NULL=nadac. | fillnull 0 as nadaa. | fillnull value="nada"The ____ command groups related events that meet various constraints. The events are grouped into ____, which are collections of events, possibly from multiple sources.Note: Same answer for both blank spaces.transactionThe following are common ____ that are used when the transaction command is used:maxspan maxpause startswith endswithconstraintsWhat command would you use at any point in the search pipeline to filter the transactions created by the transaction command?search commandThe transaction command produces two fields:1. ____: difference between the timestamps for the first and last events in the transaction.2. ____: number of events in the transaction.durationeventcountWhen using the transaction command, you can define a max overall time span and max gap between events.Which definition describes maxspan, and which describes maxpause?_____ is the maximum total time between events_____ is the maximum total time between theearliest and latest eventsmaxpausemaxspanWhat would the following indicate in an event where the transaction command is used?maxspan=5mThe maximum total time between the first and last event of all of the transactions combined should be no more than 5 minutes.To form transactions based on terms, field values, or evaluations, use ____ and ___ options. For example, if you were determining how long it took for customers to complete a purchase online over the last 24 hours you might want the FIRST event in your transactions to include "addtocart" and the LAST event to include "purchase."startswithendswith_____ can be useful when a single event does not provide enough information.transactionsTrue or False. You can use statistics and transforming commands with transactions.TrueWhen you have a choice, would you use the transaction or stats command? Why?statsit's more efficientWhich of the following definitions describe the stats command? Which definition describes the transaction command?The ____ command when you:• Need to see events correlated together• Must define event grouping based on start/end values or segment on timeThe ____ command when you:• Want to see the results of a calculation• Can group events based on a field value (e.g., by src_ip)transactionstatsThere is a limit of ____ events when using the ____ command. However there is no limit when using the ____ command.Note:first blank: #second and third blanks: pick transaction or stats1,000transactionstatsWhat’s the maximum number of events that can be grouped per transaction?a. 100 eventsb. 1,000 eventsc. 10,000 eventsb. 1,000 eventsWhat are the options that can be used to constrain transactions? Select all that apply.a. startswithb. endswithc. maxspand. maxpausec. maxspand. maxpauseWhich fields are created by the transaction command? Select all that apply.a. durationb. memcontrolc. eventcountd. txn_definitionsa. durationc. eventcountWhat are tools you use to discover and analyze various aspects of your data?knowledge objectsData interpretation, data classification, data enrichment, normalization and data sets are all different types of what?knowledge objectsWhich knowledge object deals with fields and field extractions?a. data classificationb. data setsc. data interpretationd. data enrichmentc. data interpretationWhich knowledge object deals with event types?a. data classificationb. data setsc. data interpretationd. data enrichmenta. data classificationThis type of knowledge object consists of lookups and workflow actions.a. data classificationb. data setsc. data interpretationd. data enrichmentd. data enrichmentThis type of knowledge object deals with tags and field aliases.a. data classificationb. data setsc. data interpretationd. data enrichmente. normalizatione. normalizationThis type of knowledge object contains data models.a. data classificationb. data setsc. data interpretationd. data enrichmente. normalizationb. data sets____ ___ are also persistent objects that can be used by multiple people or apps, such as macros and reports.knowledge objectsA Knowledge Object Manager could be any of the 3 Splunk roles, but a person usually has to at least be a ______.a. userb. adminc. power userc. power userSelect all knowledge objects.a. lookupsb. field aliasesc. usersd. workflow actionsa. lookupsb. field aliasesd. workflow actionsSplunk knowledge objects are persistent objects that can be used by multiple ________. Select all that apply.a. usersb. appsc. searchesa. usersb. appsSearch-time operations are always applied in the same order when generating knowledge objects. Use the following information to put search time operation in the correct order.a. Lookups b. Calculated fieldsc. Tagsd. Extractionse. Field aliasesf. Event typesd. Extractionse. Field aliasesb. Calculated fieldsa. Lookupsf. Event typesc. TagsField aliases are applied after __________, before ___________. Select all that apply.a. lookups, field extractionsb. field extractions, lookupsc. field extractions, tagsb. field extractions, lookupsc. field extractions, tagsPrior to search time in Splunk, some fields are already stored with the event in the index. ____ fields, such as host, source, and sourcetype, and ____ fields such as _time and _raw are those fields. However at search time, ____ _____extracts fields from raw event data,including those directly related to the search’s results. Use the following answers to fill in the blanks.a. internalb. field discoveryc. metac. metaa. internalb. field discoveryIn addition to the many fields Splunk auto-extracts, you can also extract your own fields with the ____ ____.(FX)Field ExtractorYou can use ___ __ to extract fields that are static and that you use often in searches.Field ExtractorYou can extract fields in FX from events using ____ and ____.regex, delimiterThe are two extraction methods in Splunk. The first, ____ is used when your event contains unstructured data like a system log file. The second, ____ is used when your event contains structured data like a .csv file.regex, delimiterYou would use _____ field extractions when a consistently structured log has values that are separated by spaces, commas, or characters.delimitedUse _________ field extractions when fields are separated by spaces, commas, or characters.a. delimitedb. regexc. renamea. delimitedThere are three ways to get to the Field Extractor (FX). Select all that apply.a. Event Actions menub. Fields sidebarc. Settings menud. Auto-Extract Fields Workflowa. Event Actions menub. Fields sidebarc. Settings menuUse ___ ____ to extract fields that are static and that you use often in searches including:-Graphical UI-Extract fields from events using regex or delimiter-Extracted fields persist as knowledge objects-Can be shared and re-used in multiple searchesField ExtractorWhen using regex for field extraction, what's the first thing you have to do in the Field Extractor?a. Select a value to extractb. Provide a Field Namec. Edit the regular expressiond. Set the Extractions Namea. Select a value to extract____ ___ are a way to associate an additional (new) name with an existing field name, like a nickname (possibly for normalization purposes), and are evaluated by the “search parser” after field extractions, before ____.field aliaseslookupsMany source types contain some type of user name. In order to make data correlation and searching easier, you can normalize the username field by using a ____ ____.field aliasPut the following steps for creating a field alias in Splunk in sequential order:a. Fieldsb. New Field Aliasc. Settingsd. Field Aliasesc. Settingsa. Fieldsd. Field Aliasesb. New Field AliasTrue or False. A new field alias is required for each sourcetype.TrueTrue or False. When you create a field alias, the original field IS affected.False. The original field is not affected.True or False. When you create a field alias, both fields appear in the all fields and Interesting Fields lists, if they appear in at least 20% of events.TrueWhen you create a field alias, both fields appear in the all fields and Interesting Fields lists, if they appear in at least ____% of events.20%After you have defined your field aliases, you can reference them in a ____ table.lookup____ fields are shortcuts for performing repetitive, long, or complex transformations using the eval command. ____ fields must be based on an extracted field.Note: Answer for both blanks are the same.calculatedWhen you create a field alias, the default behavior is that the original field is:a. overwrittenb. not affectedc. cachedb. not affectedWhen you create a calculated field, the field in the expression must be __________.a. an extracted fieldb. a lookup tablec. field/column generated from withina. an extracted field____ fields reference field aliases. ___ ____ are created to rename an existing field extraction.calculated fields, field aliasesCan you, or can't you do the following?1. Create a field alias that references a calculated field2. Create a calculated field that references a field added through a lookup operationyou CAN'TA ___ is a knowledge object that enables you to search for events that contain specific field/value combinations. They are like labels that you create for field/value pairs, and make your data more understandable and less ambiguous.tagAre tags case sensitive or case insensitive?case sensitiveTo search for a tag associated with a value you would type:a. =b. Use (*) wildcardc. tag=
c. tag=To search for a tag associated with a value on a specific field you would type:a. tag::=b. Use (*) wildcardc. tag=a. tag::=To search for a tag using a partial field value you would:a. =b. Use (*) wildcardc. tag=b. Use (*) wildcardIn order to manage tags (such as edit permissions and disable all tags for pairs) you would use the _____ ___ ____ ___ ____ menu.Note: Answer contains 5 words.List by Field Value PairHow would you change a tag name?a. by editing permissionsb. by first clicking on the field value pairc. by typing "tag="b. by first clicking on the field value pairAn ___ type is a method of categorizing events based on a search.eventCan event types be tagged?Yes, to group similar type of events
What do you use to create event types?Event Type BuilderThese are the two ways that you can ____ event types:1. Settings > Event types2. Event details > Actionstag___ ____categorize events based on a search string.Event typesIf you tag the field value of your home office’s IP address as ‘homeoffice’, what events are returned when you search for tag=homeoffice?a. events with that IP addressb. events from _internalc. field lookup tablea. events with that IP address
To search for a tag associated with a value on a specific field, select the correct search string.a. tag::user=privilegedb. tag=user==privilegedc. tag=user::privilegeda. tag::user=privilegedWhich of the following are ways you can create an event type. Select all that apply.a. Settings > Event typesb. Run a search, and save as Event Typec. From event details, select Event Actions > Build Event Typeb. Run a search, and save as Event Type_____ are useful when you frequently run searches or reports with similar search syntax, and can be a full search string or a portion of a search that can be reused in multiple places.macrosIn order to use a basic macro, you need to do the following:1. Type the macro name into the search bar2. Surround the macro name with the ______ (or grave accent) character... NOT single quotesbacktickmonthly_sales(3)The Splunker that typed the above is trying to add an argument to a macro. What have they done first in order to get the process started?added the number of arguments in parentheses after the macro nameWithin a search, macro _____ should look like the following examples:$currency$ (which would be the argument for currency)$symbol$(which would be the argument for symbol)$rate$(which would be the argument for rate)argumentsWhen using a macro with arguments, you have to include the argument(s) in _____ following the macro name and list them in the EXACT SAME order that you listed them when creating the macro.parenthesesWhen working with macros, the time range is _____________.a. Always set to Last 24 hoursb. Selected at search timec. Always set to All timeb. Selected at search timeWhen adding arguments to a macro, include the number of arguments in _____________.a. Parentheses after the macro nameb. Parentheses before the macro namec. Dollar signs within the search definitiona. Parentheses after the macro nameSurround the macro name with the _______ when executing a macro.a. Dollar signsb. Backtick characterc. Single quote characterb. Backtick characterYou can execute ____ ____ from an event or field in your search results to interact with external resources or run another search.workflow actions______ workflow actions retrieve information from an external resource.a. POSTb. GETc. Searcha. GET______ workflow actions send field values to an external resource.a. POSTb. GETc. Searcha. POST______ workflow actions use field values to perform a secondary search.a. POSTb. GETc. Searchc. SearchDo GET workflow actions have spaces or special characters?NoIn order to create GET and POST workflow actions, you have to enter the _____ (this is an acronym) for where the user will be directed. What does the acronym stand for?URI (Uniform Resource Identifier)To perform a secondary search, use a _______ workflow action.a. Searchb. POSTc. GETa. SearchWhich workflow actions require you to specify if the behavior should open in a new window or current window? Select all that apply.a. Searchb. POSTc. GETa. Searchb. POSTc. GET_____ is used for creating dashboards, and its reports are based on datasets.PivotHierarchically structured datasets used in Pivot that contain searches and fields are called _____ _____ (two words). Each event, search, or transaction is saved as a separate ______ (one word).data modelsdata setThe following are the 3 types of ____ that a data model can consist of.EventsSearchesTransactionsdatasetsWhich type of dataset contains constraints and fields?a. Eventsb. Transactionsc. Searchesa. Events_____ in "event" datasets are essentially a search broken down into a hierarchy. ____ are associated with the events.constraintsfieldsDataset fields are inherited from ____ ____.a. data modelsb. parent objectsc. root eventsa. parent objectsThe inherited attributes in the root event of a data model are called _____ fields.defaultYou can add fields to a dataset through the auto-extracted menu, eval expression, lookup, regular expression and Geo IP. Which of the following is described below?can be default fields or manually extracted fields...a. lookupb. auto-extractedc. Geo IPd. regular expressione. eval expressionb. auto-extractedWhich method of adding fields to a data set is described below?leverage an existing lookup table...a. lookupb. auto-extractedc. Geo IPd. regular expressione. eval expressiona. lookupWhich method of adding fields to a data set is described below?add geographical fields such as latitude/longitude, country, etc. ...a. lookupb. auto-extractedc. Geo IPd. regular expressione. eval expressionc. Geo IPWhich method of adding fields to a data set is described below?a new field based on an expression that you define...a. lookupb. auto-extractedc. Geo IPd. regular expressione. eval expressione. eval expressionWhich method of adding fields to a data set is described below?extract a new field based on regex...a. lookupb. auto-extractedc. Geo IPd. regular expressione. eval expressiond. regular expressionThis tool in the Splunk platform allows you to examine the overall stats of your search, examine how your search was processed and see where Splunk spent its time. You can use this tool to troubleshoot a search’s performance and understand impact of knowledge objects on processing.Search Job Inspector ToolThe 3 components of the Search Job Inspector tool are (select all that apply):a. Headerb. Field Namec. Execution costsd. Search job propertiese. Tagsa. Headerc. Execution costd. Search job propertiesThis component of the Job Search Inspector tool in Splunk provides basic information, including time to run and # of events scanned.HeaderThis component of the Job Search Inspector tool provides details on cost to retrieve results, such as:command.search.indexcommand.search.filtercommand.search.rawdataExecution Costs
The chart and timechart commands automatically filter results to include how many of the highest values?a. fifteenb. tenc. fiveb. tenAfter the chart and timechart commands automatically filter results to include the ten highest values, surplus values are grouped into...a. otherb. nullc. nota. otherA ____ allows you to overlay a computed moving average on a chart. An example of one of these are stock market visualizations.trendline____ reports are used for creating reports and dashboards. They are also based on datasets.Pivot___ ____ are hierarchically structured datasets containing searches and fields. Each event, search, or transaction is saved as a separate dataset.data modelsA data model can consist of 3 types of datasets. Select answers from below.a. eventsb. field valuesc. searchesd. field namese. lookupsf. transactionsa. eventsc. searchesf. transactionsWhich type of dataset that's used in Pivot contain constraints and fields?a. eventsb. field valuesc. searchesd. field namese. lookupsf. transactionsa. eventsIn data models events, ____ are search terms used to further narrow your search, while fields are associated with the events.constraintsYou can add more fields when creating a data model. There are four types of fields that you can add. Read the descriptions below and match the fields below with the correct description.1. a new field based on an expression that you define2. geographical fields such as latitude/longitude, country, etc.3. default fields or manually extracted fields4. a new field based on regex5. leverage an existing lookup tablea. Auto-Extractedb. Eval Expressionc. Lookupd. Regular Expressione. Geo IPb. Eval Expressione. Geo IPa. Auto-Extractedd. Regular Expressionc. LookupWhich type of Pivot dataset defines a dataset based on a search that includes transforming commands?a. eventb. field valuec. searchd. field namee. lookupf. transactionc. searchWhich type of Pivot dataset defines a dataset based on a transaction?a. eventb. field valuec. searchd. field namee. lookupf. transactionf. transactionA ___ event dataset represents a set of data that is defined by a constraint: a simple search that filters out events that aren't relevant to the dataset.root____ views allows you to create table datasets without using SPL.tableThe Splunk ______ _____ _____ (CIM) provides a methodology to normalize dataCommon Information Model____ is leveraged when creating field extractions, field aliases, event types, and tags to ensure:1. Multiple apps can co-exist on a single Splunk deployment2. Object permissions can be set to global for the use of multiple apps3. Easier and more efficient correlation of data from different sources and source typesCIM (Common Information Model)True or False. If other apps in a Splunk environment are CIM compliant, then data is normalized across apps, making it easier to search for similar data.TrueTrue or False. If other apps in a Splunk environment are NOT CIM compliant, then field aliases, tags, and event types can be used to normalize dataTrueThe Splunk CIM Add-on has a set of ___ pre-configured data models.Note: Answer is a number26The ____ should be leveraged so that knowledge objects in multiple apps can co-exist on a single Splunk deployment.CIM or Common Information ModelWhat commands can be used to retrieve data from a specified data model dataset? Choose the answers below.a. fieldsb. transformingc. fromd. datamodel
c. fromd. datamodelThe CIM ___ and ___ commands are generating commands, meaning that they have to be the first command in the pipeline.a. fieldsb. transformingc. fromd. datamodelc. fromd. datamodelThe Common Information Model ____ command retrieves data from a named dataset, saved search, report or lookup file.a. fromb. datamodela. fromThe Common Information Model ____ command allows users to examine data models and search data model datasets.a. fromb. datamodelb. datamodelSelect the available ways you can validate against a data model. Select all that apply.a. | datamodelb. Pivotc. | transactiond. Workflow actionsa. | datamodelWhat are the primary knowledge objects the CIM includes or relies upon? Select all that apply.a. data modelsb. field aliases and tagsc. event typesd. field extractionsb. field aliases and tagsc. event typesd. field extractionsA data model can consist of the following three types of datasets. Select all that apply.a. eventsb. searchesc. Pivot reportsd. transactionsa. eventsb. searchesd. transactionsTo add a Root Event Dataset, what field is required to be manually added?a. Dataset Nameb. Dataset IDc. Duration maxpause maxspanc. Duration maxpause maxspan2. Data models contain the following. Select all that apply.a. inherited and extracted fieldsb. constraintsc. event object hierarchyb. constraintsc. event object hierarchyThe transaction command produces additional fields such as:_____ which is the difference between the timestamps for the first and last event in a transactionand_____ which is the number of events in a transactiona. timeb. durationc. evencountd. fieldb. durationc. evencountWhat command creates a single correlated event from a group of events based on the same field value?transaction commandWhat are the Boolean operators that can be used by the eval command?The Splunk search processing language (SPL) supports the Boolean operators: AND , OR , and NOT . The operators must be capitalized. The AND operator is always implied between terms, that is: web error is the same as web AND error .
...
Order of evaluation.. What does eval command in Splunk?Splunk eval command. In the simplest words, the Splunk eval command can be used to calculate an expression and puts the value into a destination field. If the destination field matches to an already existing field name, then it overwrites the value of the matched field with the eval expression's result.
Which of the following functions must be used with the in function in Splunk?To use IN with the eval and where commands, you must use IN as an eval function. The Splunk documentation calls it the "in function". And the syntax and usage are slightly different than with the search command. The IN function returns TRUE if one of the values in the list matches a value in the field you specify.
How do you create a new field in Splunk using eval?Create a Calculated Field from Splunk Web. Select Settings > Fields.. Select Calculated Fields > + Add New.. Then, select the app that will use the calculated field.. Select host, source, or sourcetype to apply to the calculated field and specify a name. ... . Enter the name for the resultant calculated field.. |