3 Months Free Update
3 Months Free Update
3 Months Free Update
Which Splunk component would one use to perform line breaking prior to indexing?
When using a directory monitor input, specific source types can be selectively overridden using which configuration file?
After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?
Which default Splunk role could be assigned to provide users with the following capabilities?
Create saved searches
Edit shared objects and alerts
Not allowed to create custom roles
When using license pools, volume allocations apply to which Splunk components?
A user is assigned two roles with the following search filters. What is the user's applied search filter?
Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
An admin oversees an environment with a 1000 GBI day license. The configuration file
server.conf has strict pool quota=false set. The license is divided into the following three pools, and today's usage is shown on the right-hand column:
PoolLicense SizeToday's usage
X500 GB/day100 GB
Y350 GB/day400 GB
Z150 GB/day300 GB
Given this, which pool(s) are issued warnings?
Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?
In a distributed environment, which Splunk component is used to distribute apps and configurations to the
other Splunk instances?
Which Splunk component(s) would break a stream of syslog inputs into individual events? (select all that apply)
Which of the following are methods for adding inputs in Splunk? (select all that apply)
Windows can prevent a Splunk forwarder from reading open files. If files need to be read while they are being written to, what type of input stanza needs to be created?
If an update is made to an attribute in inputs.conf on a universal forwarder, on which Splunk component
would the fishbucket need to be reset in order to reindex the data?
Load balancing on a Universal Forwarder is not scaling correctly. The forwarder's outputs. and the tcpout stanza are setup correctly. What else could be the cause of this scaling issue? (select all that apply)
A new forwarder has been installed with a manually createddeploymentclient.conf.
What is the next step to enable the communication between the forwarder and the deployment server?
Which Splunk forwarder type allows parsing of data before forwarding to an indexer?
All search-time field extractions should be specified on which Splunk component?
Which setting allows the configuration of Splunk to allow events to span over more than one line?
What is the correct order of index time precedence?
(For each of the following, highest precedence is shown at the top and lowest precedence is shown at the bottom)
Which of the following are available input methods when adding a file input in Splunk Web? (Choose all that
apply.)
Which of the following is an appropriate description of a deployment server in a non-cluster environment?
After configuring a universal forwarder to communicate with an indexer, which index can be checked via the Splunk Web UI for a successful connection?
A non-clustered Splunk environment has three indexers (A,B,C) and two search heads (X, Y). During a search executed on search head X, indexer A crashes. What is Splunk's response?
Which of the following is the use case for the deployment server feature of Splunk?
A configuration file in a deployed app needs to be directly edited. Which steps would ensure a successful deployment to clients?
Which forwarder is recommended by Splunk to use in a production environment?
Who provides the Application Secret, Integration, and Secret keys, as well as the API Hostname when setting
up Duo for Multi-Factor Authentication in Splunk Enterprise?
When enabling data integrity control, where does Splunk Enterprise store the hash files for each bucket?
A log file contains 193 days worth of timestamped events. Which monitor stanza would be used to collect data 45 days old and newer from that log file?
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
Which of the following methods will connect a deployment client to a deployment server? (select all that apply)
What happens when there are conflicting settings within two or more configuration files?
The CLI command splunk add forward-server indexer:
which configuration file?
Where should apps be located on the deployment server that the clients pull from?
What are the values forhostandindexfor[stanza1]used by Splunk during index time, given the following configuration files?