Which of the following is a benefit of distributed search?
When using a directory monitor input, specific source types can be selectively overridden using which configuration file?
Who provides the Application Secret, Integration, and Secret keys, as well as the API Hostname when setting
up Duo for Multi-Factor Authentication in Splunk Enterprise?
Event processing occurs at which phase of the data pipeline?
In this example, if useACK is set to true and the maxQueueSize is set to 7MB, what is the size of the wait queue on this universal forwarder?
Which of the following are required when defining an index in indexes. conf? (select all that apply)
The CLI command splunk add forward-server indexer:
which configuration file?
In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?
Event example:
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
Which configuration file would be used to forward the Splunk internal logs from a search head to the indexer?
Which of the following are reasons to create separate indexes? (Choose all that apply.)
What is required when adding a native user to Splunk? (select all that apply)
Which of the following enables compression for universal forwarders in outputs. conf ?
A)
B)
C)
D)
Which forwarder is recommended by Splunk to use in a production environment?
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs
the following search over the last 24 hours:
index=*
What field can the administrator check to see the data distribution?
What is a role in Splunk? (select all that apply)
Immediately after installation, what will a Universal Forwarder do first?
Which forwarder type can parse data prior to forwarding?
Which of the following apply to how distributed search works? (select all that apply)
Which of the following indexes come pre-configured with Splunk Enterprise? (select all that apply)
When deploying apps, which attribute in the forwarder management interface determines the apps that clients install?
Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?
To set up a Network input in Splunk, what needs to be specified'?
Syslog files are being monitored on a Heavy Forwarder.
Where would the appropriate TRANSFORMS setting be deployed to reroute logs based on the event message?
What happens when there are conflicting settings within two or more configuration files?
Which of the following monitor inputs stanza headers would match all of the following files?
/var/log/www1/secure.log
/var/log/www/secure.l
/var/log/www/logs/secure.logs
/var/log/www2/secure.log
There is a file with a vast amount of old data. Which of the following inputs.conf attributes would allow an admin to monitor the file for updates without indexing the pre-existing data?
A non-clustered Splunk environment has three indexers (A,B,C) and two search heads (X, Y). During a search executed on search head X, indexer A crashes. What is Splunk's response?
The following stanzas in inputs. conf are currently being used by a deployment client:
[udp: //145.175.118.177:1001
Connection_host = dns
sourcetype = syslog
Which of the following statements is true of data that is received via this input?
Which pathway represents where a network input in Splunk might be found?
After how many warnings within a rolling 30-day period will a license violation occur with an enforced
Enterprise license?
In inputs. conf, which stanza would mean Splunk was only reading one local file?
Which of the following Splunk components require a separate installation package?
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
Which of the following are supported options when configuring optional network inputs?
Which layers are involved in Splunk configuration file layering? (select all that apply)
Which setting in indexes. conf allows data retention to be controlled by time?
Which of the following is the use case for the deployment server feature of Splunk?
What is the default character encoding used by Splunk during the input phase?
All search-time field extractions should be specified on which Splunk component?
A user recently installed an application to index NCINX access logs. After configuring the application, they realize that no data is being ingested. Which configuration file do they need to edit to ingest the access logs to ensure it remains unaffected after upgrade?
Using SEDCMD in props.conf allows raw data to be modified. With the given event below, which option will mask the first three digits of the AcctID field resulting output: [22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Event:
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
A new forwarder has been installed with a manually created deploymentclient.conf.
What is the next step to enable the communication between the forwarder and the deployment server?
Which Splunk forwarder type allows parsing of data before forwarding to an indexer?
What are the values for host and index for [stanza1] used by Splunk during index time, given the following configuration files?
A security team needs to ingest a static file for a specific incident. The log file has not been collected previously and future updates to the file must not be indexed.
Which command would meet these needs?
When working with an indexer cluster, what changes with the global precedence when comparing to a standalone deployment?
What is the valid option for a [monitor] stanza in inputs.conf?
Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
What is the command to reset the fishbucket for one source?
If an update is made to an attribute in inputs.conf on a universal forwarder, on which Splunk component
would the fishbucket need to be reset in order to reindex the data?
Which of the following are available input methods when adding a file input in Splunk Web? (Choose all that
apply.)
When running the command shown below, what is the default path in which deployment server. conf is created?
splunk set deploy-poll deployServer:port
Which parent directory contains the configuration files in Splunk?
When running a real-time search, search results are pulled from which Splunk component?
Which of the following configuration files are used with a universal forwarder? (Choose all that apply.)