All search-time field extractions should be specified on which Splunk component?
If an update is made to an attribute in inputs.conf on a universal forwarder, on which Splunk component
would the fishbucket need to be reset in order to reindex the data?
Which Splunk component would one use to perform line breaking prior to indexing?
In a distributed environment, which Splunk component is used to distribute apps and configurations to the
other Splunk instances?
A Universal Forwarder is collecting two separate sources of data (A,B). Source A is being routed through a Heavy Forwarder and then to an indexer. Source B is being routed directly to the indexer. Both sets of data require the masking of raw text strings before being written to disk. What does the administrator need to do to
ensure that the masking takes place successfully?
Which default Splunk role could be assigned to provide users with the following capabilities?
Create saved searches
Edit shared objects and alerts
Not allowed to create custom roles
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
What are the values for host and index for [stanza1] used by Splunk during index time, given the following configuration files?
Which of the following enables compression for universal forwarders in outputs. conf ?
A)
B)
C)
D)
What event-processing pipelines are used to process data for indexing? (select all that apply)
A user recently installed an application to index NCINX access logs. After configuring the application, they realize that no data is being ingested. Which configuration file do they need to edit to ingest the access logs to ensure it remains unaffected after upgrade?
After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?
What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?
The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require
multiple indexers. Following best practices, which types of Splunk component instances are needed?
Which of the following statements apply to directory inputs? {select all that apply)
Which feature in Splunk allows Event Breaking, Timestamp extractions, and any advanced configurations
found in props.conf to be validated all through the UI?
A Splunk administrator has been tasked with developing a retention strategy to have frequently accessed data sets on SSD storage and to have older, less frequently accessed data on slower NAS storage. They have set a mount point for the NAS. Which parameter do they need to modify to set the path for the older, less frequently accessed data in indexes.conf?
Which of the following Splunk components require a separate installation package?
Which layers are involved in Splunk configuration file layering? (select all that apply)
An add-on has configured field aliases for source IP address and destination IP address fields. A specific user prefers not to have those fields present in their user context. Based on the default props.conf below, which SPLUNK_HOME/etc/users/buttercup/myTA/local/props.conf stanza can be added to the user’s local context to disable the field aliases?
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
Which file will be matched for the following monitor stanza in inputs. conf?
[monitor: ///var/log/*/bar/*. txt]
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
In case of a conflict between a whitelist and a blacklist input setting, which one is used?
When configuring HTTP Event Collector (HEC) input, how would one ensure the events have been indexed?
The universal forwarder has which capabilities when sending data? (select all that apply)
Which option on the Add Data menu is most useful for testing data ingestion without creating inputs.conf?
When running a real-time search, search results are pulled from which Splunk component?
Which of the following are required when defining an index in indexes. conf? (select all that apply)
In this example, if useACK is set to true and the maxQueueSize is set to 7MB, what is the size of the wait queue on this universal forwarder?
Which setting allows the configuration of Splunk to allow events to span over more than one line?
During search time, which directory of configuration files has the highest precedence?
When running the command shown below, what is the default path in which deployment server. conf is created?
splunk set deploy-poll deployServer:port
Within props. conf, which stanzas are valid for data modification? (select all that apply)
A new forwarder has been installed with a manually created deploymentclient.conf.
What is the next step to enable the communication between the forwarder and the deployment server?
A non-clustered Splunk environment has three indexers (A,B,C) and two search heads (X, Y). During a search executed on search head X, indexer A crashes. What is Splunk's response?