3 Months Free Update
3 Months Free Update
3 Months Free Update
A Splunk administrator has been tasked with developing a retention strategy to have frequently accessed data sets on SSD storage and to have older, less frequently accessed data on slower NAS storage. They have set a mount point for the NAS. Which parameter do they need to modify to set the path for the older, less frequently accessed data in indexes.conf?
Syslog files are being monitored on a Heavy Forwarder.
Where would the appropriate TRANSFORMS setting be deployed to reroute logs based on the event message?
When running a real-time search, search results are pulled from which Splunk component?
When deploying apps, which attribute in the forwarder management interface determines the apps that clients install?
When configuring HTTP Event Collector (HEC) input, how would one ensure the events have been indexed?
Which forwarder is recommended by Splunk to use in a production environment?
After how many warnings within a rolling 30-day period will a license violation occur with an enforced
Enterprise license?
Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?
Which artifact is required in the request header when creating an HTTP event?
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
Who provides the Application Secret, Integration, and Secret keys, as well as the API Hostname when setting
up Duo for Multi-Factor Authentication in Splunk Enterprise?
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
When using a directory monitor input, specific source type can be selectively overridden using which configuration file?
Which Splunk component would one use to perform line breaking prior to indexing?
In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?
Event example:
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
When using a directory monitor input, specific source types can be selectively overridden using which configuration file?
A Universal Forwarder has the following active stanza in inputs . conf:
[monitor: //var/log]
disabled = O
host = 460352847
An event from this input has a timestamp of 10:55. What timezone will Splunk add to the event as part of indexing?
A user recently installed an application to index NCINX access logs. After configuring the application, they realize that no data is being ingested. Which configuration file do they need to edit to ingest the access logs to ensure it remains unaffected after upgrade?
Within props. conf, which stanzas are valid for data modification? (select all that apply)
Which of the following types of data count against the license daily quota?
What happens when the same username exists in Splunk as well as through LDAP?
An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data
is 300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the
index?
Which configuration file would be used to forward the Splunk internal logs from a search head to the indexer?
Which of the following is an appropriate description of a deployment server in a non-cluster environment?
Which authentication methods are natively supported within Splunk Enterprise? (select all that apply)
In this example, if useACK is set to true and the maxQueueSize is set to 7MB, what is the size of the wait queue on this universal forwarder?
Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)
Search heads in a company's European offices need to be able to search data in their New York offices. They also need to restrict access to certain indexers. What should be configured to allow this type of action?
User role inheritance allows what to be inherited from the parent role? (select all that apply)
Which of the following accurately describes HTTP Event Collector indexer acknowledgement?
Which of the following are reasons to create separate indexes? (Choose all that apply.)
What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?
What type of Splunk license is pre-selected in a brand new Splunk installation?
An add-on has configured field aliases for source IP address and destination IP address fields. A specific user prefers not to have those fields present in their user context. Based on the default props.conf below, which SPLUNK_HOME/etc/users/buttercup/myTA/local/props.conf stanza can be added to the user’s local context to disable the field aliases?
Which of the following are supported configuration methods to add inputs on a forwarder? (select all that apply)