Which of the following are reasons to create separate indexes? (Choose all that apply.)
Which layers are involved in Splunk configuration file layering? (select all that apply)
Given a forwarder with the following outputs.conf configuration:
[tcpout : mypartner]
Server = 145.188.183.184:9097
[tcpout : hfbank]
server = inputsl . mysplunkhfs . corp : 9997 , inputs2 . mysplunkhfs . corp : 9997
Which of the following is a true statement?
Which artifact is required in the request header when creating an HTTP event?
A Universal Forwarder is collecting two separate sources of data (A,B). Source A is being routed through a Heavy Forwarder and then to an indexer. Source B is being routed directly to the indexer. Both sets of data require the masking of raw text strings before being written to disk. What does the administrator need to do to
ensure that the masking takes place successfully?
The universal forwarder has which capabilities when sending data? (select all that apply)
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?
Which Splunk component performs indexing and responds to search requests from the search head?
Which of the following apply to how distributed search works? (select all that apply)
Which data pipeline phase is the last opportunity for defining event boundaries?
Load balancing on a Universal Forwarder is not scaling correctly. The forwarder's outputs. and the tcpout stanza are setup correctly. What else could be the cause of this scaling issue? (select all that apply)
In addition to single, non-clustered Splunk instances, what else can the deployment server push apps to?
Which forwarder is recommended by Splunk to use in a production environment?
Which optional configuration setting in inputs .conf allows you to selectively forward the data to specific indexer(s)?
When running the command shown below, what is the default path in which deployment server. conf is created?
splunk set deploy-poll deployServer:port
How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON
A)
B)
C)
D)
What event-processing pipelines are used to process data for indexing? (select all that apply)
When configuring monitor inputs with whitelists or blacklists, what is the supported method of filtering the lists?
Which of the following configuration files are used with a universal forwarder? (Choose all that apply.)
All search-time field extractions should be specified on which Splunk component?
What is an example of a proper configuration for CHARSET within props.conf?
During search time, which directory of configuration files has the highest precedence?
When running a real-time search, search results are pulled from which Splunk component?
A user recently installed an application to index NCINX access logs. After configuring the application, they realize that no data is being ingested. Which configuration file do they need to edit to ingest the access logs to ensure it remains unaffected after upgrade?
Which feature in Splunk allows Event Breaking, Timestamp extractions, and any advanced configurations
found in props.conf to be validated all through the UI?
When working with an indexer cluster, what changes with the global precedence when comparing to a standalone deployment?
Where should apps be located on the deployment server that the clients pull from?
Which scenario is applicable given the stanzas in authentication.conf below?
[authentication]
externalTwoFactorAuthVendor = Duo
externalTwoFactorAuthSettings = duoMFA
[duoMFA]
integrationKey = aGFwcHliaXJ0aGRheU1pZGR5
secretKey = YXVzdHJhaWxpYW5Gb3JHcmVw
applicationKey = c3BsaW5raW5ndGhlcGx1bWJ1c3NpbmN1OTU
apiHostname = 466993018.duosecurity.com
failOpen = True
timeout = 60
A Splunk administrator has been tasked with developing a retention strategy to have frequently accessed data sets on SSD storage and to have older, less frequently accessed data on slower NAS storage. They have set a mount point for the NAS. Which parameter do they need to modify to set the path for the older, less frequently accessed data in indexes.conf?
A configuration file in a deployed app needs to be directly edited. Which steps would ensure a successful deployment to clients?
In this example, if useACK is set to true and the maxQueueSize is set to 7MB, what is the size of the wait queue on this universal forwarder?
After how many warnings within a rolling 30-day period will a license violation occur with an enforced
Enterprise license?