Services
Discover
Homeschooling
Ask a Question
Log in
Sign up
Filters
Done
Question type:
Essay
Multiple Choice
Short Answer
True False
Matching
Topic
Certification
Study Set
Splunk
Exam 3: Splunk Certified Developer
Path 4
Access For Free
Share
All types
Filters
Study Flashcards
Practice Exam
Learn
Question 41
Multiple Choice
This file has been manually created on a universal forwarder: /opt/splunkforwarder/etc/apps/my_TA/local/inputs.conf [monitor:///var/log/messages] sourcetype=syslog index=syslog A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new inputs.conf file: /opt/splunk/etc/deployment-apps/my_TA/local/inputs.conf [monitor:///var/log/maillog] sourcetype=maillog Which file is now monitored?
Question 42
Multiple Choice
The CLI command splunk add forward-server indexer:<receiving-port> will create stanza(s) in which configuration file?
Question 43
Multiple Choice
When does a warm bucket roll over to a cold bucket?
Question 44
Multiple Choice
What is the valid option for a [monitor] stanza in inputs.conf ?
Question 45
Multiple Choice
Which setting in indexes.conf allows data retention to be controlled by time?
Question 46
Multiple Choice
Who provides the Application Secret, Integration, and Secret keys, as well as the API Hostname when setting up Duo for Multi-Factor Authentication in Splunk Enterprise?
Question 47
Multiple Choice
Which feature in Splunk allows Event Breaking, Timestamp extractions, and any advanced configurations found in props.conf to be validated all through the UI?
Question 48
Multiple Choice
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs the following search over the last 24 hours: index=* What field can the administrator check to see the data distribution?
Question 49
Multiple Choice
The universal forwarder has which capabilities when sending data? (Select all that apply.)
Question 50
Multiple Choice
How is data handled by Splunk during the input phase of the data ingestion process?
Question 51
Multiple Choice
Which parent directory contains the configuration files in Splunk?
Question 52
Multiple Choice
An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data is 300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the index?
Question 53
Multiple Choice
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?