In which Splunk configuration is the SEDCMD used?
Where are deployment server apps mapped to clients?
When Splunk is integrated with LDAP, which attribute can be changed in the Splunk UI for an LDAP user?
What are the values for host and index for [stanza1] used by Splunk during index time, given the following configuration files?
The following stanzas in inputs. conf are currently being used by a deployment client:
[udp: //145.175.118.177:1001
Connection_host = dns
sourcetype = syslog
Which of the following statements is true of data that is received via this input?
This file has been manually created on a universal forwarder
A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new
Which file is now monitored?
Within props. conf, which stanzas are valid for data modification? (select all that apply)
Which of the following apply to how distributed search works? (select all that apply)
How is a remote monitor input distributed to forwarders?
When running a real-time search, search results are pulled from which Splunk component?
Which authentication methods are natively supported within Splunk Enterprise? (select all that apply)
What is the difference between the two wildcards ... and - for the monitor stanza in inputs, conf?
Which of the following is a valid distributed search group?
Which of the following statements apply to directory inputs? {select all that apply)
Which of the following configuration files are used with a universal forwarder? (Choose all that apply.)
What is the default value of LINE_BREAKER?
What action is required to enable forwarder management in Splunk Web?
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
What is the correct curl to send multiple events through HTTP Event Collector?
In this example, if useACK is set to true and the maxQueueSize is set to 7MB, what is the size of the wait queue on this universal forwarder?
When configuring HTTP Event Collector (HEC) input, how would one ensure the events have been indexed?
What will the following inputs. conf stanza do?
[script://myscript . sh]
Interval=0
In addition to single, non-clustered Splunk instances, what else can the deployment server push apps to?
A user recently installed an application to index NCINX access logs. After configuring the application, they realize that no data is being ingested. Which configuration file do they need to edit to ingest the access logs to ensure it remains unaffected after upgrade?
How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON
A)
B)
C)
D)
Which of the following describes a Splunk deployment server?
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
Which of the following enables compression for universal forwarders in outputs. conf ?
A)
B)
C)
D)
Consider the following stanza in inputs.conf:
What will the value of the source filed be for events generated by this scripts input?
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
Which file will be matched for the following monitor stanza in inputs. conf?
[monitor: ///var/log/*/bar/*. txt]
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
During search time, which directory of configuration files has the highest precedence?
How do you remove missing forwarders from the Monitoring Console?
Which configuration file would be used to forward the Splunk internal logs from a search head to the indexer?
In a distributed environment, which Splunk component is used to distribute apps and configurations to the
other Splunk instances?
An admin oversees an environment with a 1000 GBI day license. The configuration file
server.conf has strict pool quota=false set. The license is divided into the following three pools, and today's usage is shown on the right-hand column:
PoolLicense SizeToday's usage
X500 GB/day100 GB
Y350 GB/day400 GB
Z150 GB/day300 GB
Given this, which pool(s) are issued warnings?
What event-processing pipelines are used to process data for indexing? (select all that apply)
What is required when adding a native user to Splunk? (select all that apply)
User role inheritance allows what to be inherited from the parent role? (select all that apply)
Which of the following are available input methods when adding a file input in Splunk Web? (Choose all that
apply.)
Which of the following statements describe deployment management? (select all that apply)
Search heads in a company's European offices need to be able to search data in their New York offices. They also need to restrict access to certain indexers. What should be configured to allow this type of action?
Which default Splunk role could be assigned to provide users with the following capabilities?
Create saved searches
Edit shared objects and alerts
Not allowed to create custom roles
Which optional configuration setting in inputs .conf allows you to selectively forward the data to specific indexer(s)?
Which Splunk component(s) would break a stream of syslog inputs into individual events? (select all that apply)
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?
Which of the following is a valid method to create a Splunk user?
Which of the following types of data count against the license daily quota?
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?
What is the command to reset the fishbucket for one source?
What is the correct order of steps in Duo Multifactor Authentication?
Where should apps be located on the deployment server that the clients pull from?
To set up a Network input in Splunk, what needs to be specified'?
What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?