What are the three main Splunk components?
A. Search head, indexer, forwarder
B. Search head, SQL database, forwarder
C. Search head, SSD, heavy weight agent
D. Search head, GPU, streamer
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
What determines the scope of data that appears in a scheduled report?
A. The owner of the report can configure permissions so that the report uses either the User role or the owner's profile at run time.
B. All data accessible to all users will appear in the report until the next time the report is run.
C. All data accessible to the User role will appear in the report.
D. All data accessible to the owner of the report will appear in the report.
正解:A
質問 3:
Which search matches the events containing the terms "error" and "fail"?
A. index=security error OR fail
B. index=security "error failure"
C. index=security NOT error NOT fail
D. index=security Error Fail
正解:D
質問 4:
Which of the statements is correct regarding click and drag option in timeline?
A. This doesn't execute a new query
B. The new result after selecting the range by dragging filters the events and displays the most recent first.
C. There is no functionality like click and drag in Splunk's timeline.
D. Using this option executes a new query.
正解:B
質問 5:
Select the best options for "search best practices" in Splunk:
(Choose five.)
A. Try to specify index values.
B. Never select time range.
C. Select the time range always.
D. Try to use * with every search term.
E. Try to keep specific search terms.
F. Inclusion is generally better than exclusion.
G. Include as many search terms as possible.
正解:A,C,E,F,G
Sagawa -
Pass4Test様に大感謝です。先日貴社のサイトにはSPLK-1001を購入しました。家で独学し、ひたすら問題を繰り返し練習することで、試験に合格することができました。おかげさまです。ありがとうございました。