3 Months Free Update
3 Months Free Update
3 Months Free Update
Which of the following indexes come pre-configured with Splunk Enterprise? (select all that apply)
A Universal Forwarder has the following active stanza in inputs . conf:
[monitor: //var/log]
disabled = O
host = 460352847
An event from this input has a timestamp of 10:55. What timezone will Splunk add to the event as part of indexing?
What is required when adding a native user to Splunk? (select all that apply)
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs
the following search over the last 24 hours:
index=*
What field can the administrator check to see the data distribution?
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
When enabling data integrity control, where does Splunk Enterprise store the hash files for each bucket?
Assume a file is being monitored and the data was incorrectly indexed to an exclusive index. The index is
cleaned and now the data must be reindexed. What other index must be cleaned to reset the input checkpoint
information for that file?
Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
You update a props. conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btoo1 props list —debug. What will the output be?
What is the correct curl to send multiple events through HTTP Event Collector?
When deploying apps on Universal Forwarders using the deployment server, what is the correct component and location of the app before it is deployed?
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
Which of the following is true when authenticating users to Splunk using LDAP?
Which optional configuration setting in inputs .conf allows you to selectively forward the data to specific indexer(s)?
Which data pipeline phase is the last opportunity for defining event boundaries?
The following stanzas in inputs. conf are currently being used by a deployment client:
[udp: //145.175.118.177:1001
Connection_host = dns
sourcetype = syslog
Which of the following statements is true of data that is received via this input?
Which artifact is required in the request header when creating an HTTP event?
Which of the following methods will connect a deployment client to a deployment server? (select all that apply)
Which forwarder is recommended by Splunk to use in a production environment?
During search time, which directory of configuration files has the highest precedence?
There is a file with a vast amount of old data. Which of the following inputs.conf attributes would allow an admin to monitor the file for updates without indexing the pre-existing data?
An admin oversees an environment with a 1000 GBI day license. The configuration file
server.conf has strict pool quota=false set. The license is divided into the following three pools, and today's usage is shown on the right-hand column:
PoolLicense SizeToday's usage
X500 GB/day100 GB
Y350 GB/day400 GB
Z150 GB/day300 GB
Given this, which pool(s) are issued warnings?
When deploying apps, which attribute in the forwarder management interface determines the apps that clients install?
If an update is made to an attribute in inputs.conf on a universal forwarder, on which Splunk component
would the fishbucket need to be reset in order to reindex the data?
Which file will be matched for the following monitor stanza in inputs. conf?
[monitor: ///var/log/*/bar/*. txt]
All search-time field extractions should be specified on which Splunk component?
Which scenario is applicable given the stanzas in authentication.conf below?
[authentication]
externalTwoFactorAuthVendor = Duo
externalTwoFactorAuthSettings = duoMFA
[duoMFA]
integrationKey = aGFwcHliaXJ0aGRheU1pZGR5
secretKey = YXVzdHJhaWxpYW5Gb3JHcmVw
applicationKey = c3BsaW5raW5ndGhlcGx1bWJ1c3NpbmN1OTU
apiHostname = 466993018.duosecurity.com
failOpen = True
timeout = 60
Which Splunk component(s) would break a stream of syslog inputs into individual events? (select all that apply)
When using license pools, volume allocations apply to which Splunk components?
UsingSEDCMDinprops.confallows raw data to be modified. With the given event below, which option will mask the first three digits of theAcctIDfield resulting output:[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Event:
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?
Which of the following are supported options when configuring optional network inputs?
After configuring a universal forwarder to communicate with an indexer, which index can be checked via the Splunk Web UI for a successful connection?
Which of the following apply to how distributed search works? (select all that apply)
Which of the following configuration files are used with a universal forwarder? (Choose all that apply.)
What happens when there are conflicting settings within two or more configuration files?
Which of the following types of data count against the license daily quota?
Which of the following statements describe deployment management? (select all that apply)
A configuration file in a deployed app needs to be directly edited. Which steps would ensure a successful deployment to clients?
A non-clustered Splunk environment has three indexers (A,B,C) and two search heads (X, Y). During a search executed on search head X, indexer A crashes. What is Splunk's response?
A Splunk administrator has been tasked with developing a retention strategy to have frequently accessed data sets on SSD storage and to have older, less frequently accessed data on slower NAS storage. They have set a mount point for the NAS. Which parameter do they need to modify to set the path for the older, less frequently accessed data in indexes.conf?
On the deployment server, administrators can map clients to server classes using client filters. Which of the
following statements is accurate?
Which Splunk configuration file is used to enable data integrity checking?
When Splunk is integrated with LDAP, which attribute can be changed in the Splunk UI for an LDAP user?
After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?