Exam SPLK-1001 All QuestionsBrowse all questions from this exam
Question 54

In a deployment with multiple indexes, what will happen when a search is run and an index is not specified in the search string?

    Correct Answer: D

    In a deployment with multiple indexes, if an index is not specified in the search string, events from every index searched by default to which the user has access will be returned. This is because Splunk applies default settings that include searching through all available indexes the user has permission to access unless specified otherwise.

Discussion
Janna05Option: D

D is correct pag 42 Splunk applies defaults if not specified

SimonR2Option: D

Just tested this and it returned all results from indexes I had access to. Answer is D.

Sanket3Option: D

D is correct it will take default index if not specified

BrynnMLOption: D

D is correct

ShreeshaKMOption: A

Answer is A. Splunk will not return any events.

NanilaOption: D

Page 42 of the PDF says, Splunk applies default if not specified. So D is accurate

FrancoPepeOption: A

I have 2 indexes in my test deployment. (Splunk enterprise) 9.1.0.2. By running a simple search with the word "error" or a sourcetype specified does not return any event. To me it's A

NiketesOption: D

Splunk Cloud, version 9. Tried a search putting a sourcetype before, then one with only a word after, without telling the index: I got result. So for me D is the correct one.

daniele_pepeOption: A

A. Splunk 9 returns no event

pabinajmOption: A

Using Splunk 8.1.1, when I don’t specify an index, I don’t get results. I’ve created two new indexes, both which contain data, but neither are searched by default.

pabinajm

In order to establish new indexes as “default”, edit the Role > Indexes, check the indexes to be made default.

alisyedOption: D

Because you only have one index in your Lab. Try to create a test Index and then search. It will search both the test and default index

gcalcaterraOption: D

In my lab with splunk 8, when I don't specify any index param it only brings me data from the default index "main". So I'm confused with this one? any other tests?

yury

Is the assumption that you have access to all/remaining Indexes?