What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
After an Enterprise Trial license expires, it will automatically convert to a Free license. How many days is an Enterprise Trial license valid before this conversion occurs?
During search time, which directory of configuration files has the highest precedence?
What is required when adding a native user to Splunk? (select all that apply)
Which optional configuration setting in inputs .conf allows you to selectively forward the data to specific indexer(s)?
What is the correct curl to send multiple events through HTTP Event Collector?
Which of the following types of data count against the license daily quota?
Which of the following apply to how distributed search works? (select all that apply)
A Universal Forwarder is collecting two separate sources of data (A,B). Source A is being routed through a Heavy Forwarder and then to an indexer. Source B is being routed directly to the indexer. Both sets of data require the masking of raw text strings before being written to disk. What does the administrator need to do to
ensure that the masking takes place successfully?
When using license pools, volume allocations apply to which Splunk components?
A user recently installed an application to index NCINX access logs. After configuring the application, they realize that no data is being ingested. Which configuration file do they need to edit to ingest the access logs to ensure it remains unaffected after upgrade?
What is the order of precedence (from lowest → highest) within serverclass.conf in which attributes will be expressed?
Which of the following is the use case for the deployment server feature of Splunk?
Which forwarder is recommended by Splunk to use in a production environment?
There is a file with a vast amount of old data. Which of the following inputs.conf attributes would allow an admin to monitor the file for updates without indexing the pre-existing data?
In addition to single, non-clustered Splunk instances, what else can the deployment server push apps to?
Which of the following is true when authenticating users to Splunk using LDAP?
Running this search in a distributed environment:
On what Splunk component does the eval command get executed?
This file has been manually created on a universal forwarder

A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new

Which file is now monitored?
Which of the following are supported options when configuring optional network inputs?
A Universal Forwarder has the following active stanza in inputs . conf:
[monitor: //var/log]
disabled = O
host = 460352847
An event from this input has a timestamp of 10:55. What timezone will Splunk add to the event as part of indexing?
Which Splunk component(s) would break a stream of syslog inputs into individual events? (select all that apply)
After configuring a universal forwarder to communicate with an indexer, which index can be checked via the Splunk Web UI for a successful connection?
Which of the following statements accurately describes using SSL to secure the feed from a forwarder?
All search-time field extractions should be specified on which Splunk component?
What is the difference between the two wildcards ... and - for the monitor stanza in inputs, conf?
Where should apps be located on the deployment server that the clients pull from?
Which option accurately describes the purpose of the HTTP Event Collector (HEC)?
A request has been made to restrict lookup files up to 500 megabytes for replication. Anything larger should not be replicated. Which of the following parameters provides the correct control for this scenario?
Which of the following are available input methods when adding a file input in Splunk Web? (Choose all that
apply.)
An admin oversees an environment with a 1000 GBI day license. The configuration file
server.conf has strict pool quota=false set. The license is divided into the following three pools, and today's usage is shown on the right-hand column:
PoolLicense SizeToday's usage
X500 GB/day100 GB
Y350 GB/day400 GB
Z150 GB/day300 GB
Given this, which pool(s) are issued warnings?
Which of the following Splunk components require a separate installation package?
Which of the following are required when defining an index in indexes. conf? (select all that apply)
Which Splunk configuration file is used to enable data integrity checking?
Which of the following statements describe deployment management? (select all that apply)
How is data handled by Splunk during the input phase of the data ingestion process?
The CLI command splunk add forward-server indexer:
which configuration file?
When configuring monitor inputs with whitelists or blacklists, what is the supported method of filtering the lists?
Which configuration file would be used to forward the Splunk internal logs from a search head to the indexer?
Which of the following is the recommended guideline for creating a new user role?
Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as
follows: 123-44-5678.
Which configuration file and stanza pair will mask possible SSNs in the log events?
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?