Categories
Uncategorized

Splunk – User Exam Preparation

Exam Outline

The Splunk core certified user exam covers eight domains:

  • Splunk Basics – 5%
  • Basic Searching – 22%
  • Using Fields in Searches – 20%
  • Search Language Fundamentals – 15%
  • Using Basic Transforming Commands – 15%
  • Creating Reports and Dashboards – 12 %
  • Creating and Using Lookups – 6%
  • Creating Scheaduled Reports and alerts – 5%

Example questions

  1. What are the main components of Splunk?
    1. Splunk forwarder, indexer, search head
    2. Splunk indexer, heavy forwarder, search head
    3. Splunk indexer, deployment manager, forwarder
    4. Splunk heavy forwarder, deployment manager, splunk indexer
  2. When you install Splunk on a stand-alone machine, which components are on it?
    1. input data
    2. parser
    3. indexer
    4. all of the above
  3. When you install the Splunk Enterprise free 60-day trial version, what is you daily index size?
    1. 100 MB
    2. 500 MB
    3. 750 MB
    4. 1000 MB
  4. A ………….. displays statistical trends over time.
    1. chart value
    2. time series
    3. stats value
    4. table value
  5. The …………. command can display any series of data you want to plot.
    1. chart
    2. stat
    3. time chart
    4. both 1 and 2
  6. Which are filtering commands in Splunk?
    1. where, dedup, and head
    2. dedup, head, and tail
    3. where, dedup, and tail
    4. all of the above
  7. A transaction is a grouping command.
    1. true
    2. false

More about exam

Notes:

  • Splunk basics – componets, usages, apps, add-ons, customizing user settings, basic navigation in Splunk.
  • Basic Searching – run basic search, time range, search results, refine searches, timeline, events, search job, save search results.
  • Using Fields in Searches – fields, fields in searches, sidebar.
  • Search Language Fundamentals – general search practices, basic search commands, search pipeline, indexes in search, table, rename, fields, dedup, sort.
  • Using basic transforming commands – top, rare, stats.
  • Creating Reports and Dashboards – save a search as a report, edit reports, create reports to display statistics, visualizations, charts, add a report to a dashboard, edit dashboard.
  • Creating and Using Lookups – lookups, lookup file, lookup definition, automatic lookup, lookup in searches.
  • Creating Scheaduled Reports and Alerts – scheduled report, configuration of scheduled reports, alerts.

Sources

Sources (Examples of questions):

  • https://docs.splunk.com/Documentation/Splunk/8.1.2/SearchReference/Stats
  • https://www.apress.com/gp/book/9781484266687
  • https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transaction

Some sources for test preparations:

  • https://www.testpreptraining.com/tutorial/splunk-core-certified-user-splk-1001/
  • https://vceguide.com/splunk/
  • https://www.examtopics.com/exams/splunk/splk-1001/view/
  • https://www.itexams.com/info/SPLK-1001
  • https://www.itexams.com/exam/SPLK-1001

Exam: – https://wsr.pearsonvue.com/