A log file contains 193 days worth of timestamped events. Which monitor stanza would be used to collect data 45 days old and newer from that log file?
What is the difference between the two wildcards ... and - for the monitor stanza in inputs, conf?
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?
Which of the following are methods for adding inputs in Splunk? (select all that apply)
Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as
follows: 123-44-5678.
Which configuration file and stanza pair will mask possible SSNs in the log events?
After configuring a universal forwarder to communicate with an indexer, which index can be checked via the Splunk Web UI for a successful connection?
What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?
When deploying apps, which attribute in the forwarder management interface determines the apps that clients install?
Load balancing on a Universal Forwarder is not scaling correctly. The forwarder's outputs. and the tcpout stanza are setup correctly. What else could be the cause of this scaling issue? (select all that apply)
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
What event-processing pipelines are used to process data for indexing? (select all that apply)
How is data handled by Splunk during the input phase of the data ingestion process?
After how many warnings within a rolling 30-day period will a license violation occur with an enforced
Enterprise license?
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
A user recently installed an application to index NCINX access logs. After configuring the application, they realize that no data is being ingested. Which configuration file do they need to edit to ingest the access logs to ensure it remains unaffected after upgrade?
A configuration file in a deployed app needs to be directly edited. Which steps would ensure a successful deployment to clients?
In this example, if useACK is set to true and the maxQueueSize is set to 7MB, what is the size of the wait queue on this universal forwarder?
Where should apps be located on the deployment server that the clients pull from?
Assume a file is being monitored and the data was incorrectly indexed to an exclusive index. The index is
cleaned and now the data must be reindexed. What other index must be cleaned to reset the input checkpoint
information for that file?
Which Splunk component performs indexing and responds to search requests from the search head?
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?
Which optional configuration setting in inputs .conf allows you to selectively forward the data to specific indexer(s)?
Which of the following indexes come pre-configured with Splunk Enterprise? (select all that apply)
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
In inputs. conf, which stanza would mean Splunk was only reading one local file?
This file has been manually created on a universal forwarder
A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new
Which file is now monitored?
During search time, which directory of configuration files has the highest precedence?
What will the following inputs. conf stanza do?
[script://myscript . sh]
Interval=0
Which option accurately describes the purpose of the HTTP Event Collector (HEC)?
Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?
The universal forwarder has which capabilities when sending data? (select all that apply)
What are the minimum required settings when creating a network input in Splunk?
Which of the following methods will connect a deployment client to a deployment server? (select all that apply)
Which Splunk component(s) would break a stream of syslog inputs into individual events? (select all that apply)
Which Splunk component distributes apps and certain other configuration updates to search head cluster members?