What are the values forhostandindexfor[stanza1]used by Splunk during index time, given the following configuration files?
You update a props. conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btoo1 props list —debug. What will the output be?
A user is assigned two roles with the following search filters. What is the user ' s applied search filter?
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
Which of the following are available input methods when adding a file input in Splunk Web? (Choose all that
apply.)
A Universal Forwarder has the following active stanza in inputs . conf:
[monitor: //var/log]
disabled = O
host = 460352847
An event from this input has a timestamp of 10:55. What timezone will Splunk add to the event as part of indexing?
Given a forwarder with the following outputs.conf configuration:
[tcpout : mypartner]
Server = 145.188.183.184:9097
[tcpout : hfbank]
server = inputsl . mysplunkhfs . corp : 9997 , inputs2 . mysplunkhfs . corp : 9997
Which of the following is a true statement?
Which of the following are supported configuration methods to add inputs on a forwarder? (select all that apply)
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
Where can scripts for scripted inputs reside on the host file system? (select all that apply)
When working with an indexer cluster, what changes with the global precedence when comparing to a standalone deployment?
UsingSEDCMDinprops.confallows raw data to be modified. With the given event below, which option will mask the first three digits of theAcctIDfield resulting output:[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Event:
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Seven different network switches are sending traffic to a server hosting a Universal Forwarder . Three of the devices are sending TCP data and four of the devices are sending UDP data.
What is the minimum number of input stanzas that must be created on the Universal Forwarder to successfully capture data from all seven sources?
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
What happens when there are conflicting settings within two or more configuration files?
Which Splunk component would one use to perform line breaking prior to indexing?
When using a directory monitor input, specific source types can be selectively overridden using which configuration file?
On the deployment server, administrators can map clients to server classes using client filters. Which of the
following statements is accurate?
Which of the following is an acceptable channel value when using the HTTP Event Collector indexer acknowledgment capability?
After how many warnings within a rolling 30-day period will a license violation occur with an enforced
Enterprise license?
After an Enterprise Trial license expires, it will automatically convert to a Free license. How many days is an Enterprise Trial license valid before this conversion occurs?
What is the correct order of index time precedence?
(For each of the following, highest precedence is shown at the top and lowest precedence is shown at the bottom)
Which authentication methods are natively supported within Splunk Enterprise? (select all that apply)
A Universal Forwarder is monitoring a very active syslog stream and as a result is unable to switch between destinations. How would an admin safely remediate this issue?
Which of the following enables compression for universal forwarders in outputs. conf ?
A)
B)
C)
D)
When restarting services, the Splunk Enterprise instance reports that there is a “typo in stanza.†Which Splunk command will help locate the error?
When running the command shown below, what is the default path in which deployment server. conf is created?
splunk set deploy-poll deployServer:port
All search-time field extractions should be specified on which Splunk component?
Which of the following is true regarding LDAP integration with Splunk Enterprise?
What options are available when creating custom roles? (select all that apply)
Which of the following are methods for adding inputs in Splunk? (select all that apply)
A request has been made to restrict lookup files up to 500 megabytes for replication . Anything larger should not be replicated . Which of the following parameters provides the correct control for this scenario?
Which of the following monitor inputs stanza headers would match all of the following files?
/var/log/www1/secure.log
/var/log/www/secure.l
/var/log/www/logs/secure.logs
/var/log/www2/secure.log
Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as
follows: 123-44-5678.
Which configuration file and stanza pair will mask possible SSNs in the log events?
User role inheritance allows what to be inherited from the parent role? (select all that apply)
A Universal Forwarder is collecting two separate sources of data (A,B). Source A is being routed through a Heavy Forwarder and then to an indexer. Source B is being routed directly to the indexer. Both sets of data require the masking of raw text strings before being written to disk. What does the administrator need to do to
ensure that the masking takes place successfully?
Which options for Multifactor Authentication, also known as MFA, are available in Splunk Enterprise?
A user recently installed an application to index NCINX access logs. After configuring the application, they realize that no data is being ingested. Which configuration file do they need to edit to ingest the access logs to ensure it remains unaffected after upgrade?
What is an example of a proper configuration for CHARSET within props.conf?
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
An index stores its data in buckets. Which default directories does Splunk use to store buckets? (Choose all that apply.)
For single line event sourcetypes. it is most efficient to set SHOULD_linemerge to what value?
Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)