A log file contains 193 days worth of timestamped events. Which monitor stanza would be used to collect data 45 days old and newer from that log file?
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs
the following search over the last 24 hours:
index=*
What field can the administrator check to see the data distribution?
Which setting allows the configuration of Splunk to allow events to span over more than one line?
Which of the following statements apply to directory inputs? {select all that apply)
What are the values forhostandindexfor[stanza1]used by Splunk during index time, given the following configuration files?
Which of the following are available input methods when adding a file input in Splunk Web? (Choose all that
apply.)
What is required when adding a native user to Splunk? (select all that apply)
Given a forwarder with the following outputs.conf configuration:
[tcpout : mypartner]
Server = 145.188.183.184:9097
[tcpout : hfbank]
server = inputsl . mysplunkhfs . corp : 9997 , inputs2 . mysplunkhfs . corp : 9997
Which of the following is a true statement?
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
What will the following inputs. conf stanza do?
[script://myscript . sh]
Interval=0
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?
A Universal Forwarder is collecting two separate sources of data (A,B). Source A is being routed through a Heavy Forwarder and then to an indexer. Source B is being routed directly to the indexer. Both sets of data require the masking of raw text strings before being written to disk. What does the administrator need to do to
ensure that the masking takes place successfully?
In inputs. conf, which stanza would mean Splunk was only reading one local file?
What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?
Windows can prevent a Splunk forwarder from reading open files. If files need to be read while they are being written to, what type of input stanza needs to be created?
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
When configuring monitor inputs with whitelists or blacklists, what is the supported method of filtering the lists?
Where can scripts for scripted inputs reside on the host file system? (select all that apply)
Consider the following stanza ininputs.conf:
What will the value of the source filed be for events generated by this scripts input?
Which Splunk configuration file is used to enable data integrity checking?
Which of the following apply to how distributed search works? (select all that apply)
When configuring HTTP Event Collector (HEC) input, how would one ensure the events have been indexed?
Where should apps be located on the deployment server that the clients pull from?
Which Splunk component would one use to perform line breaking prior to indexing?
Which of the following is the use case for the deployment server feature of Splunk?
When running a real-time search, search results are pulled from which Splunk component?
After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?
Which of the following accurately describes HTTP Event Collector indexer acknowledgement?
The CLI command splunk add forward-server indexer:
which configuration file?
Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
The universal forwarder has which capabilities when sending data? (select all that apply)
Load balancing on a Universal Forwarder is not scaling correctly. The forwarder's outputs. and the tcpout stanza are setup correctly. What else could be the cause of this scaling issue? (select all that apply)
Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?
Which of the following are supported configuration methods to add inputs on a forwarder? (select all that apply)
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
UsingSEDCMDinprops.confallows raw data to be modified. With the given event below, which option will mask the first three digits of theAcctIDfield resulting output:[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Event:
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
A non-clustered Splunk environment has three indexers (A,B,C) and two search heads (X, Y). During a search executed on search head X, indexer A crashes. What is Splunk's response?
Which file will be matched for the following monitor stanza in inputs. conf?
[monitor: ///var/log/*/bar/*. txt]