New Year Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

SPLK-1005 Splunk Cloud Certified Admin Questions and Answers

Questions 4

In which of the following situations should Splunk Support be contacted?

Options:

A.

When a custom search needs tuning due to not performing as expected.

B.

When an app on Splunkbase indicates Request Install.

C.

Before using the delete command.

D.

When a new role that mirrors sc_admin is required.

Buy Now
Questions 5

Which of the following methods is valid for creating index-time field extractions?

Options:

A.

Use the UI to create a sourcetype, specify the field name and corresponding regular expression with capture statement.

B.

Create a configuration app with the index-time props.conf and/or transfoms. conf, and upload the app via UI.

C.

Use the CU app to define settings in fields.conf, and restart Splunk Cloud.

D.

Use the rex command to extract the desired field, and then save as a calculated field.

Buy Now
Questions 6

Which of the following is not a path used by Splunk to execute scripts?

Options:

A.

SPLUNK_HOME/etc/system/bin

B.

SPLUNK HOME/etc/appa//bin

C.

SPLUNKHOMS/ctc/scripts/local

D.

SPLUNK_HOME/bin/scripts

Buy Now
Questions 7

Which of the following are features of a managed Splunk Cloud environment?

Options:

A.

Availability of premium apps, no IP address whitelisting or blacklisting, deployed in US East AWS region.

B.

20GB daily maximum data ingestion, no SSO integration, no availability of premium apps.

C.

Availability of premium apps, SSO integration, IP address whitelisting and blacklisting.

D.

Availability of premium apps, SSO integration, maximum concurrent search limit of 20.

Buy Now
Questions 8

By default, which of the following capabilities are granted to the sc_admin role?

Options:

A.

indexes_edit, edit___token, admin_all_objects, delete_by_keyword

B.

indexes_edit, fsh_manage, acs_conf, list_indexesdiscovert

C.

indexes_edit, fsh_manage, admin_all_objects can_delete

D.

indexes_edit, edit_token_http, admin _all objects, edit limits_conf

Buy Now
Questions 9

Li was asked to create a Splunk configuration to monitor syslog files stored on Linux servers at their organization. This configuration will be pushed out to multiple systems via a Splunk app using the on-prem deployment server.

The system administrators have provided Li with a directory listing for the logging locations on three syslog hosts, which are representative of the file structure for all systems collecting this data. An example from each system is shown below:

SPLK-1005 Question 9

A)

SPLK-1005 Question 9

B)

SPLK-1005 Question 9

C)

SPLK-1005 Question 9

D)

SPLK-1005 Question 9

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 10

Which of the following is a valid stanza in props. conf?

Options:

A.

[sourcetype::linux_secure]

B.

[host=nyc25]

C.

[host::nyc*]

D.

[host:nyc*]

Buy Now
Questions 11

When using Splunk Universal Forwarders, which of the following is true?

Options:

A.

No more than six Universal Forwarders may connect directly to Splunk Cloud.

B.

Any number of Universal Forwarders may connect directly to Splunk Cloud.

C.

Universal Forwarders must send data to an Intermediate Forwarder.

D.

There must be one Intermediate Forwarder for every three Universal Forwarders.

Buy Now
Questions 12

What is the recommended method to test the onboarding of a new data source before putting it in production?

Options:

A.

Send test data to a test index.

B.

Send data to the associated production index.

C.

Replicate Splunk deployment in a test environment.

D.

Send data to the chance index.

Buy Now
Questions 13

The following Apache access log is being ingested into Splunk via a monitor input:

SPLK-1005 Question 13

How does Splunk determine the time zone for this event?

Options:

A.

The value of the TZ attribute in props. cont for the a :ces3_ccwbined sourcetype.

B.

The value of the TZ attribute in props, conf for the my.webserver.example host.

C.

The time zone of the Heavy/Intermediate Forwarder with the monitor input.

D.

The time zone indicator in the raw event data.

Buy Now
Questions 14

In which file can the SH0ULD_LINEMERCE setting be modified?

Options:

A.

transforms.conf

B.

inputs.conf

C.

props.conf

D.

outputs.conf

Buy Now
Questions 15

Which statement is true about monitor inputs?

Options:

A.

Monitor inputs are configured in the monitor, conf file.

B.

The ignoreOlderThan option allows files to be ignored based on the file modification time.

C.

The crSalt setting is required.

D.

Monitor inputs can ignore a file's existing content, indexing new data as it arrives, by configuring the tailProcessor option.

Buy Now
Questions 16

Given the following set of files, which of the monitor stanzas below will result in Splunk monitoring all of the files ending with .log?

Files:

    /var/log/www1/secure.log

    /var/log/www1/access.log

    /var/log/www2/logs/secure.log

    /var/log/www2/access.log

    /var/log/www2/access.log.1

Options:

A.

[monitor:///var/log/*/*.log]

B.

[monitor:///var/log/.../*.log]

C.

[monitor:///var/log/*/*]

D.

[monitor:///var/log/.../*]

Buy Now
Questions 17

Which of the following statements is true about data transformations using SEDCMD?

Options:

A.

Can only be used to mask or truncate raw data.

B.

Configured in props.conf and transform.conf.

C.

Can be used to manipulate the sourcetype per event.

D.

Operates on a REGEX pattern match of the source, sourcetype, or host of an event.

Buy Now
Questions 18

When adding a directory monitor and specifying a sourcetype explicitly, it applies to all files in the directory and subdirectories. If automatic sourcetyping is used, a user can selectively override it in which file on the forwarder?

Options:

A.

transforms.conf

B.

props.conf

C.

inputs.conf

D.

outputs.cont

Buy Now
Questions 19

Where does the regex replacement processor run?

Options:

A.

Merging pipeline

B.

Typing pipeline

C.

Index pipeline

D.

Parsing pipeline

Buy Now
Questions 20

Where can an administrator download the Splunk Cloud Universal Forwarder credentials package?

Options:

A.

Splunk Support.

B.

Cloud Monitoring Console forwarder drop-down.

C.

Universal Forwarder app in the Splunk Cloud search head.

D.

Splunkbase.

Buy Now
Questions 21

Which of the following statements is true regarding sedcmd?

Options:

A.

SEDCMD can be defined in either props.conf or transforms.conf.

B.

SEDCMD does not work on Windows-based installations of Splunk.

C.

SEDCMD uses the same syntax as Splunk's replace command.

D.

SEDCMD provides search and replace functionality using regular expressions and substitutions.

Buy Now
Questions 22

When monitoring network inputs, there will be times when the forwarder is unable to send data to the indexers. Splunk uses a memory queue and a disk queue. Which setting is used for the disk queue?

Options:

A.

queueSize

B.

maxQeueSize

C.

diskQiioiioiiizo

D.

persistentQueueSize

Buy Now
Questions 23

Which of the following are valid settings for file and directory monitor inputs?

A)

SPLK-1005 Question 23

B)

SPLK-1005 Question 23

C)

SPLK-1005 Question 23

D)

SPLK-1005 Question 23

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 24

Which of the following is a valid method to test if a forwarder can successfully send data to Splunk Cloud?

Options:

A.

Search the _audit index to confirm whether the forwarder ID was registered.

B.

Use oneshot from the CLI on the forwarders, then check to see if those logs show up in the Splunk Cloud environment.

C.

On Splunk Cloud UI, click Add Data and upload a test file, then search to see if the logs show up.

D.

Ping the inputssl.example.splunkcloud.com to see if it returns the ping.

Buy Now
Exam Code: SPLK-1005
Exam Name: Splunk Cloud Certified Admin
Last Update: Dec 20, 2024
Questions: 80

PDF + Testing Engine

$57.75  $164.99

Testing Engine

$43.75  $124.99
buy now SPLK-1005 testing engine

PDF (Q&A)

$36.75  $104.99
buy now SPLK-1005 pdf