There is a file with a vast amount of old data. Which of the following inputs.conf attributes would allow an admin to monitor the file for updates without indexing the pre-existing data?
What happens when there are conflicting settings within two or more configuration files?
An admin oversees an environment with a 1000 GBI day license. The configuration file
server.conf has strict pool quota=false set. The license is divided into the following three pools, and today's usage is shown on the right-hand column:
PoolLicense SizeToday's usage
X500 GB/day100 GB
Y350 GB/day400 GB
Z150 GB/day300 GB
Given this, which pool(s) are issued warnings?
A Splunk administrator has been tasked with developing a retention strategy to have frequently accessed data sets on SSD storage and to have older, less frequently accessed data on slower NAS storage. They have set a mount point for the NAS. Which parameter do they need to modify to set the path for the older, less frequently accessed data in indexes.conf?
How is data handled by Splunk during the input phase of the data ingestion process?
A user is assigned two roles with the following search filters. What is the user's applied search filter?
Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?
All search-time field extractions should be specified on which Splunk component?
In this example, ifuseACKis set to true and themaxQueueSizeis set to 7MB, what is the size of the wait queue on this universal forwarder?
After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?
What is the correct order of index time precedence?
(For each of the following, highest precedence is shown at the top and lowest precedence is shown at the bottom)
Which of the following are supported options when configuring optional network inputs?
Which of the following is true when authenticating users to Splunk using LDAP?
Which of the following enables compression for universal forwarders in outputs. conf ?
A)
B)
C)
D)
Which option accurately describes the purpose of the HTTP Event Collector (HEC)?
In addition to single, non-clustered Splunk instances, what else can the deployment server push apps to?
Which of the following apply to how distributed search works? (select all that apply)
User role inheritance allows what to be inherited from the parent role? (select all that apply)
UsingSEDCMDinprops.confallows raw data to be modified. With the given event below, which option will mask the first three digits of theAcctIDfield resulting output:[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Event:
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs
the following search over the last 24 hours:
index=*
What field can the administrator check to see the data distribution?
In case of a conflict between a whitelist and a blacklist input setting, which one is used?
Which data pipeline phase is the last opportunity for defining event boundaries?
For single line event sourcetypes. it is most efficient to set SHOULD_linemerge to what value?
Which layers are involved in Splunk configuration file layering? (select all that apply)
When running a real-time search, search results are pulled from which Splunk component?
Which default Splunk role could be assigned to provide users with the following capabilities?
Create saved searches
Edit shared objects and alerts
Not allowed to create custom roles
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?
Which of the following are methods for adding inputs in Splunk? (select all that apply)
Which of the following configuration files are used with a universal forwarder? (Choose all that apply.)
A company moves to a distributed architecture to meet the growing demand for the use of Splunk. What parameter can be configured to enable automatic load balancing in the
Universal Forwarder to send data to the indexers?
Which artifact is required in the request header when creating an HTTP event?
When enabling data integrity control, where does Splunk Enterprise store the hash files for each bucket?
Which Splunk component distributes apps and certain other configuration updates to search head cluster members?
What is required when adding a native user to Splunk? (select all that apply)
Search heads in a company's European offices need to be able to search data in their New York offices. They also need to restrict access to certain indexers. What should be configured to allow this type of action?
Which of the following is the recommended guideline for creating a new user role?
When deploying apps, which attribute in the forwarder management interface determines the apps that clients install?
Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)
Which of the following lists the three phases of the Splunk Indexing process in order?
The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require
multiple indexers. Following best practices, which types of Splunk component instances are needed?
Which Splunk forwarder type allows parsing of data before forwarding to an indexer?
The CLI command splunk add forward-server indexer:
which configuration file?
This file has been manually created on a universal forwarder
A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new
Which file is now monitored?
Consider the following stanza ininputs.conf:
What will the value of the source filed be for events generated by this scripts input?
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?