Which of the following is a benefit of distributed search?
Which authentication methods are natively supported within Splunk Enterprise? (select all that apply)
In this example, ifuseACKis set to true and themaxQueueSizeis set to 7MB, what is the size of the wait queue on this universal forwarder?
What are the values forhostandindexfor[stanza1]used by Splunk during index time, given the following configuration files?
The following stanzas in inputs. conf are currently being used by a deployment client:
[udp: //145.175.118.177:1001
Connection_host = dns
sourcetype = syslog
Which of the following statements is true of data that is received via this input?
What will the following inputs. conf stanza do?
[script://myscript . sh]
Interval=0
What is a role in Splunk? (select all that apply)
Which of the following statements accurately describes using SSL to secure the feed from a forwarder?
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
Running this search in a distributed environment:
On what Splunk component does the eval command get executed?
What happens when there are conflicting settings within two or more configuration files?
Which of the following is valid distribute search group?
A)
B)
C)
D)
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
How does the Monitoring Console monitor forwarders?
Which of the following statements apply to directory inputs? {select all that apply)
What action is required to enable forwarder management in Splunk Web?
How can native authentication be disabled in Splunk?
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?
Given a forwarder with the following outputs.conf configuration:
[tcpout : mypartner]
Server = 145.188.183.184:9097
[tcpout : hfbank]
server = inputsl . mysplunkhfs . corp : 9997 , inputs2 . mysplunkhfs . corp : 9997
Which of the following is a true statement?
A user is assigned two roles with the following search filters. What is the user's applied search filter?
Which of the following is a valid method to create a Splunk user?
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
The priority of layered Splunk configuration files depends on the file's:
Which of the following enables compression for universal forwarders in outputs. conf ?
A)
B)
C)
D)
Search heads in a company's European offices need to be able to search data in their New York offices. They also need to restrict access to certain indexers. What should be configured to allow this type of action?
What conf file needs to be edited to set up distributed search groups?
An admin oversees an environment with a 1000 GBI day license. The configuration file
server.conf has strict pool quota=false set. The license is divided into the following three pools, and today's usage is shown on the right-hand column:
PoolLicense SizeToday's usage
X500 GB/day100 GB
Y350 GB/day400 GB
Z150 GB/day300 GB
Given this, which pool(s) are issued warnings?
When running the command shown below, what is the default path in which deployment server. conf is created?
splunk set deploy-poll deployServer:port
During search time, which directory of configuration files has the highest precedence?
A security team needs to ingest a static file for a specific incident. The log file has not been collected previously and future updates to the file must not be indexed.
Which command would meet these needs?
Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?
Which of the methods listed below supports muti-factor authentication?
Which of the following applies only to Splunk index data integrity check?
Local user accounts created in Splunk store passwords in which file?
To set up a Network input in Splunk, what needs to be specified'?
After how many warnings within a rolling 30-day period will a license violation occur with an enforced
Enterprise license?
You update a props. conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btoo1 props list —debug. What will the output be?
Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?
A Universal Forwarder is collecting two separate sources of data (A,B). Source A is being routed through a Heavy Forwarder and then to an indexer. Source B is being routed directly to the indexer. Both sets of data require the masking of raw text strings before being written to disk. What does the administrator need to do to
ensure that the masking takes place successfully?
Which of the following is a valid distributed search group?
Which Splunk component does a search head primarily communicate with?
Consider the following stanza ininputs.conf:
What will the value of the source filed be for events generated by this scripts input?
When should the Data Preview feature be used?
Which forwarder is recommended by Splunk to use in a production environment?
What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?
Which valid bucket types are searchable? (select all that apply)
What is the default value ofLINE_BREAKER?
In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?
Event example:
A non-clustered Splunk environment has three indexers (A,B,C) and two search heads (X, Y). During a search executed on search head X, indexer A crashes. What is Splunk's response?
Which of the following apply to how distributed search works? (select all that apply)
The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require
multiple indexers. Following best practices, which types of Splunk component instances are needed?
Which default Splunk role could be assigned to provide users with the following capabilities?
Create saved searches
Edit shared objects and alerts
Not allowed to create custom roles
Which setting in indexes. conf allows data retention to be controlled by time?
An add-on has configured field aliases for source IP address and destination IP address fields. A specific user prefers not to have those fields present in their user context. Based on the defaultprops.confbelow, whichSPLUNK_HOME/etc/users/buttercup/myTA/local/props.confstanza can be added to the user’s local context to disable the field aliases?
What options are available when creating custom roles? (select all that apply)
When are knowledge bundles distributed to search peers?
Syslog files are being monitored on a Heavy Forwarder.
Where would the appropriate TRANSFORMS setting be deployed to reroute logs based on the event message?
On the deployment server, administrators can map clients to server classes using client filters. Which of the
following statements is accurate?