How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON
A)
B)
C)
D)
Which of the following is an appropriate description of a deployment server in a non-cluster environment?
In addition to single, non-clustered Splunk instances, what else can the deployment server push apps to?
Which of the following must be done to define user permissions when integrating Splunk with LDAP?
Which Splunk component performs indexing and responds to search requests from the search head?
Which of the following are methods for adding inputs in Splunk? (select all that apply)
In a distributed environment, which Splunk component is used to distribute apps and configurations to the
other Splunk instances?
An add-on has configured field aliases for source IP address and destination IP address fields. A specific user prefers not to have those fields present in their user context. Based on the default props.conf below, which SPLUNK_HOME/etc/users/buttercup/myTA/local/props.conf stanza can be added to the user’s local context to disable the field aliases?
After how many warnings within a rolling 30-day period will a license violation occur with an enforced
Enterprise license?
The priority of layered Splunk configuration files depends on the file's:
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
Which Splunk forwarder has a built-in license?
Which of the following are reasons to create separate indexes? (Choose all that apply.)
An index stores its data in buckets. Which default directories does Splunk use to store buckets? (Choose all that apply.)
Which Splunk component does a search head primarily communicate with?
Which setting allows the configuration of Splunk to allow events to span over more than one line?
What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?
Which of the following accurately describes HTTP Event Collector indexer acknowledgement?
What options are available when creating custom roles? (select all that apply)
What is the default value of LINE_BREAKER?
When using a directory monitor input, specific source type can be selectively overridden using which configuration file?
Which data pipeline phase is the last opportunity for defining event boundaries?
In which phase do indexed extractions in props.conf occur?
Immediately after installation, what will a Universal Forwarder do first?
In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?
Event example:
What happens when there are conflicting settings within two or more configuration files?
A user recently installed an application to index NCINX access logs. After configuring the application, they realize that no data is being ingested. Which configuration file do they need to edit to ingest the access logs to ensure it remains unaffected after upgrade?
Which is a valid stanza for a network input?
During search time, which directory of configuration files has the highest precedence?
Which of the following configuration files are used with a universal forwarder? (Choose all that apply.)
Which optional configuration setting in inputs .conf allows you to selectively forward the data to specific indexer(s)?
Which Splunk component would one use to perform line breaking prior to indexing?
Immediately after installation, what will a Universal Forwarder do first?
Load balancing on a Universal Forwarder is not scaling correctly. The forwarder's outputs. and the tcpout stanza are setup correctly. What else could be the cause of this scaling issue? (select all that apply)
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs
the following search over the last 24 hours:
index=*
What field can the administrator check to see the data distribution?
What is the default character encoding used by Splunk during the input phase?
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
In which phase of the index time process does the license metering occur?
In which Splunk configuration is the SEDCMD used?
To set up a Network input in Splunk, what needs to be specified'?
Which of the following statements accurately describes using SSL to secure the feed from a forwarder?
What is the valid option for a [monitor] stanza in inputs.conf?
Assume a file is being monitored and the data was incorrectly indexed to an exclusive index. The index is
cleaned and now the data must be reindexed. What other index must be cleaned to reset the input checkpoint
information for that file?
Which of the following apply to how distributed search works? (select all that apply)
What conf file needs to be edited to set up distributed search groups?
Which of the following are supported configuration methods to add inputs on a forwarder? (select all that apply)
Which of the following is accurate regarding the input phase?
Which parent directory contains the configuration files in Splunk?
When would the following command be used?
Which of the following is an acceptable channel value when using the HTTP Event Collector indexer acknowledgment capability?
Which Splunk forwarder type allows parsing of data before forwarding to an indexer?
Which of the methods listed below supports muti-factor authentication?
Consider the following stanza in inputs.conf:
What will the value of the source filed be for events generated by this scripts input?
Which of the following are available input methods when adding a file input in Splunk Web? (Choose all that
apply.)
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
Which Splunk component(s) would break a stream of syslog inputs into individual events? (select all that apply)