When working with an indexer cluster, what changes with the global precedence when comparing to a standalone deployment?
For single line event sourcetypes. it is most efficient to set SHOULD_linemerge to what value?
This file has been manually created on a universal forwarder
A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new
Which file is now monitored?
Which of the following are available input methods when adding a file input in Splunk Web? (Choose all that
apply.)
Search heads in a company's European offices need to be able to search data in their New York offices. They also need to restrict access to certain indexers. What should be configured to allow this type of action?
A security team needs to ingest a static file for a specific incident. The log file has not been collected previously and future updates to the file must not be indexed.
Which command would meet these needs?
Which of the following indexes come pre-configured with Splunk Enterprise? (select all that apply)
Which artifact is required in the request header when creating an HTTP event?
The universal forwarder has which capabilities when sending data? (select all that apply)
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
Using SEDCMD in props.conf allows raw data to be modified. With the given event below, which option will mask the first three digits of the AcctID field resulting output: [22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Event:
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
What is required when adding a native user to Splunk? (select all that apply)
Which of the following must be done to define user permissions when integrating Splunk with LDAP?
Which of the following is an appropriate description of a deployment server in a non-cluster environment?
Which of the following is the use case for the deployment server feature of Splunk?
Which configuration file would be used to forward the Splunk internal logs from a search head to the indexer?
Which of the following are required when defining an index in indexes. conf? (select all that apply)
Where should apps be located on the deployment server that the clients pull from?
Which scenario is applicable given the stanzas in authentication.conf below?
[authentication]
externalTwoFactorAuthVendor = Duo
externalTwoFactorAuthSettings = duoMFA
[duoMFA]
integrationKey = aGFwcHliaXJ0aGRheU1pZGR5
secretKey = YXVzdHJhaWxpYW5Gb3JHcmVw
applicationKey = c3BsaW5raW5ndGhlcGx1bWJ1c3NpbmN1OTU
apiHostname = 466993018.duosecurity.com
failOpen = True
timeout = 60
After configuring a universal forwarder to communicate with an indexer, which index can be checked via the Splunk Web UI for a successful connection?
Given a forwarder with the following outputs.conf configuration:
[tcpout : mypartner]
Server = 145.188.183.184:9097
[tcpout : hfbank]
server = inputsl . mysplunkhfs . corp : 9997 , inputs2 . mysplunkhfs . corp : 9997
Which of the following is a true statement?
Which default Splunk role could be assigned to provide users with the following capabilities?
Create saved searches
Edit shared objects and alerts
Not allowed to create custom roles
What happens when the same username exists in Splunk as well as through LDAP?
An admin oversees an environment with a 1000 GBI day license. The configuration file
server.conf has strict pool quota=false set. The license is divided into the following three pools, and today's usage is shown on the right-hand column:
PoolLicense SizeToday's usage
X500 GB/day100 GB
Y350 GB/day400 GB
Z150 GB/day300 GB
Given this, which pool(s) are issued warnings?
During search time, which directory of configuration files has the highest precedence?
The following stanza is active in indexes.conf:
[cat_facts]
maxHotSpanSecs = 3600
frozenTimePeriodInSecs = 2630000
maxTota1DataSizeMB = 650000
All other related indexes.conf settings are default values.
If the event timestamp was 3739283 seconds ago, will it be searchable?
In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?
Event example:
A Splunk administrator has been tasked with developing a retention strategy to have frequently accessed data sets on SSD storage and to have older, less frequently accessed data on slower NAS storage. They have set a mount point for the NAS. Which parameter do they need to modify to set the path for the older, less frequently accessed data in indexes.conf?
When using a directory monitor input, specific source types can be selectively overridden using which configuration file?
What is the correct curl to send multiple events through HTTP Event Collector?
After how many warnings within a rolling 30-day period will a license violation occur with an enforced
Enterprise license?
Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
What event-processing pipelines are used to process data for indexing? (select all that apply)
An index stores its data in buckets. Which default directories does Splunk use to store buckets? (Choose all that apply.)
After an Enterprise Trial license expires, it will automatically convert to a Free license. How many days is an Enterprise Trial license valid before this conversion occurs?
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
What are the minimum required settings when creating a network input in Splunk?
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?