In addition to single, non-clustered Splunk instances, what else can the deployment server push apps to?
What is the order of precedence (from lowest → highest) within serverclass.conf in which attributes will be expressed?
A company moves to a distributed architecture to meet the growing demand for the use of Splunk. What parameter can be configured to enable automatic load balancing in the
Universal Forwarder to send data to the indexers?
What configuration file are remote Windows Management Instrumentation inputs defined in?
Which of the following statements describe deployment management? (select all that apply)
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
What is required when adding a native user to Splunk? (select all that apply)
What type of Splunk license is pre-selected in a brand new Splunk installation?
After how many warnings within a rolling 30-day period will a license violation occur with an enforced
Enterprise license?
You update a props. conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btoo1 props list —debug. What will the output be?
User role inheritance allows what to be inherited from the parent role? (select all that apply)
What are the minimum required settings when creating a network input in Splunk?
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
What options are available when creating custom roles? (select all that apply)
Which file will be matched for the following monitor stanza in inputs. conf?
[monitor: ///var/log/*/bar/*. txt]
Which of the following is the use case for the deployment server feature of Splunk?
When configuring HTTP Event Collector (HEC) input, how would one ensure the events have been indexed?
Which of the following are reasons to create separate indexes? (Choose all that apply.)
How is data handled by Splunk during the input phase of the data ingestion process?
Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)
Which data pipeline phase is the last opportunity for defining event boundaries?
Which default Splunk role could be assigned to provide users with the following capabilities?
Create saved searches
Edit shared objects and alerts
Not allowed to create custom roles
Which setting allows the configuration of Splunk to allow events to span over more than one line?
A configuration file in a deployed app needs to be directly edited. Which steps would ensure a successful deployment to clients?
In this example, ifuseACKis set to true and themaxQueueSizeis set to 7MB, what is the size of the wait queue on this universal forwarder?
The following stanzas in inputs. conf are currently being used by a deployment client:
[udp: //145.175.118.177:1001
Connection_host = dns
sourcetype = syslog
Which of the following statements is true of data that is received via this input?
An admin updates the Role to Group mapping for external authentication. How does the change affect users that are currently logged into Splunk?
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
A Universal Forwarder is monitoring a very active syslog stream and as a result is unable to switch between destinations. How would an admin safely remediate this issue?
Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
On the deployment server, administrators can map clients to server classes using client filters. Which of the
following statements is accurate?
Which Splunk component would one use to perform line breaking prior to indexing?
What is the importance of modifying Transparent Huge Pages (THP) and ulimit settings when installing Splunk Enterprise?
What action could be taken to prevent a license warning with an ingest-based license?
Within props. conf, which stanzas are valid for data modification? (select all that apply)
Which of the following statements apply to directory inputs? {select all that apply)
Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?
When running the command shown below, what is the default path in which deployment server. conf is created?
splunk set deploy-poll deployServer:port
The CLI command splunk add forward-server indexer:
which configuration file?
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as
follows: 123-44-5678.
Which configuration file and stanza pair will mask possible SSNs in the log events?