There is a file with a vast amount of old data. Which of the following inputs.conf attributes would allow an admin to monitor the file for updates without indexing the pre-existing data?
You update a props. conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btoo1 props list —debug. What will the output be?
Which of the following are supported options when configuring optional network inputs?
Which of the following are supported configuration methods to add inputs on a forwarder? (select all that apply)
A security team needs to ingest a static file for a specific incident. The log file has not been collected previously and future updates to the file must not be indexed.
Which command would meet these needs?
Which of the following statements apply to directory inputs? {select all that apply)
In addition to single, non-clustered Splunk instances, what else can the deployment server push apps to?
The following stanzas in inputs. conf are currently being used by a deployment client:
[udp: //145.175.118.177:1001
Connection_host = dns
sourcetype = syslog
Which of the following statements is true of data that is received via this input?
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data
is 300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the
index?
Which of the following are methods for adding inputs in Splunk? (select all that apply)
Which of the following accurately describes HTTP Event Collector indexer acknowledgement?
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
Which of the following is an appropriate description of a deployment server in a non-cluster environment?
A user recently installed an application to index NCINX access logs. After configuring the application, they realize that no data is being ingested. Which configuration file do they need to edit to ingest the access logs to ensure it remains unaffected after upgrade?
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
Which setting allows the configuration of Splunk to allow events to span over more than one line?
Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)
Within props. conf, which stanzas are valid for data modification? (select all that apply)
Search heads in a company's European offices need to be able to search data in their New York offices. They also need to restrict access to certain indexers. What should be configured to allow this type of action?
Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
Which scenario is applicable given the stanzas in authentication.conf below?
[authentication]
externalTwoFactorAuthVendor = Duo
externalTwoFactorAuthSettings = duoMFA
[duoMFA]
integrationKey = aGFwcHliaXJ0aGRheU1pZGR5
secretKey = YXVzdHJhaWxpYW5Gb3JHcmVw
applicationKey = c3BsaW5raW5ndGhlcGx1bWJ1c3NpbmN1OTU
apiHostname = 466993018.duosecurity.com
failOpen = True
timeout = 60
Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?
A configuration file in a deployed app needs to be directly edited. Which steps would ensure a successful deployment to clients?
When configuring monitor inputs with whitelists or blacklists, what is the supported method of filtering the lists?
In a distributed environment, which Splunk component is used to distribute apps and configurations to the
other Splunk instances?
What is the difference between the two wildcards ... and - for the monitor stanza in inputs, conf?
Which Splunk component performs indexing and responds to search requests from the search head?
Which of the following methods will connect a deployment client to a deployment server? (select all that apply)
Running this search in a distributed environment:
On what Splunk component does the eval command get executed?
What are the minimum required settings when creating a network input in Splunk?
A non-clustered Splunk environment has three indexers (A,B,C) and two search heads (X, Y). During a search executed on search head X, indexer A crashes. What is Splunk's response?
What will the following inputs. conf stanza do?
[script://myscript . sh]
Interval=0
Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as
follows: 123-44-5678.
Which configuration file and stanza pair will mask possible SSNs in the log events?
Which of the following statements describe deployment management? (select all that apply)
The CLI command splunk add forward-server indexer:
which configuration file?
When enabling data integrity control, where does Splunk Enterprise store the hash files for each bucket?
If an update is made to an attribute in inputs.conf on a universal forwarder, on which Splunk component
would the fishbucket need to be reset in order to reindex the data?