Which of the following is an acceptable channel value when using the HTTP Event Collector indexer acknowledgment capability?
A Universal Forwarder is monitoring a very active syslog stream and as a result is unable to switch between destinations. How would an admin safely remediate this issue?
What will the following inputs. conf stanza do?
[script://myscript . sh]
Interval=0
A Universal Forwarder is collecting two separate sources of data (A,B). Source A is being routed through a Heavy Forwarder and then to an indexer. Source B is being routed directly to the indexer. Both sets of data require the masking of raw text strings before being written to disk. What does the administrator need to do to
ensure that the masking takes place successfully?
How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON
A)

B)

C)

D)

A security team needs to ingest a static file for a specific incident. The log file has not been collected previously and future updates to the file must not be indexed.
Which command would meet these needs?
Where should apps be located on the deployment server that the clients pull from?
A company moves to a distributed architecture to meet the growing demand for the use of Splunk. What parameter can be configured to enable automatic load balancing in the
Universal Forwarder to send data to the indexers?
What is the order of precedence (from lowest → highest) within serverclass.conf in which attributes will be expressed?
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
Which of the following apply to how distributed search works? (select all that apply)
Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?
Which data pipeline phase is the last opportunity for defining event boundaries?
Which of the following lists the three phases of the Splunk Indexing process in order?
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
All search-time field extractions should be specified on which Splunk component?
When configuring HTTP Event Collector (HEC) input, how would one ensure the events have been indexed?
A log file contains 193 days worth of timestamped events. Which monitor stanza would be used to collect data 45 days old and newer from that log file?
What is the correct order of index time precedence?
(For each of the following, highest precedence is shown at the top and lowest precedence is shown at the bottom)
A non-clustered Splunk environment has three indexers (A,B,C) and two search heads (X, Y). During a search executed on search head X, indexer A crashes. What is Splunk's response?
Which of the following are methods for adding inputs in Splunk? (select all that apply)
Which option accurately describes the purpose of the HTTP Event Collector (HEC)?
What are the minimum required settings when creating a network input in Splunk?
An admin oversees an environment with a 1000 GBI day license. The configuration file
server.conf has strict pool quota=false set. The license is divided into the following three pools, and today's usage is shown on the right-hand column:
PoolLicense SizeToday's usage
X500 GB/day100 GB
Y350 GB/day400 GB
Z150 GB/day300 GB
Given this, which pool(s) are issued warnings?
Syslog files are being monitored on a Heavy Forwarder.
Where would the appropriate TRANSFORMS setting be deployed to reroute logs based on the event message?
Which of the following Splunk components require a separate installation package?
Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
Which of the following must be done to define user permissions when integrating Splunk with LDAP?
What happens when there are conflicting settings within two or more configuration files?
What action could be taken to prevent a license warning with an ingest-based license?
Consider the following stanza ininputs.conf:
What will the value of the source filed be for events generated by this scripts input?
Which file will be matched for the following monitor stanza in inputs. conf?
[monitor: ///var/log/*/bar/*. txt]
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
What event-processing pipelines are used to process data for indexing? (select all that apply)