Winter Special Sale - Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 575363r9

Welcome To DumpsPedia

SPLK-1005 Sample Questions Answers

Questions 4

What Splunk command will allow an administrator to view the runtime configuration instructions for a monitored file in Inputs. cont on the forwarders?

Options:

A.

./splunk _internal call /services/data/input.3/filemonitor

B.

./splunk show config inputs.conf

C.

./splunk _internal rest /services/data/inputs/monitor

D.

./splunk show config inputs

Buy Now
Questions 5

Which of the following is a correct statement about Universal Forwarders?

Options:

A.

The Universal Forwarder must be able to contact the license master.

B.

A Universal Forwarder must connect to Splunk Cloud via a Heavy Forwarder.

C.

A Universal Forwarder can be an Intermediate Forwarder.

D.

The default output bandwidth is 500KBps.

Buy Now
Questions 6

Which of the following tasks is the responsibility of a Splunk Cloud administrator?

Options:

A.

Configuring deployer

B.

Configuring cluster master

C.

Configuring indexers

D.

Configuring indexes

Buy Now
Questions 7

When monitoring directories that contain mixed file types, which setting should be omitted from inputs, conf and instead be overridden in propo.conf?

Options:

A.

sourcetype

B.

host

C.

source

D.

index

Buy Now
Questions 8

Consider the following configurations:

What is the value of the sourcetype property for this stanza based on Splunk's configuration file precedence?

Options:

A.

NULL, or unset, due to configuration conflict

B.

access_corabined

C.

linux aacurs

D.

linux_secure, access_combined

Buy Now
Questions 9

In Splunk Cloud, which of the following statements regarding REST API is true?

Options:

A.

REST API and Splunk HEC are on the same port.

B.

All REST API endpoints are open and available by default.

C.

REST API is not available in Splunk Cloud.

D.

A subset of REST API endpoints are enabled for customers to manage Splunk.

Buy Now
Questions 10

When should Splunk Cloud Support be contacted?

Options:

A.

For scripted input troubleshooting.

B.

For all configuration changes.

C.

When unable to resolve issues or perform problem isolation.

D.

For resizing, license changes, or any purchases.

Buy Now
Questions 11

When is data deleted from a Splunk Cloud index?

Options:

A.

When buckets roll to frozen, without a defined archive.

B.

When data is deleted via the Splunk Cloud Admin GUI.

C.

When TA_Delete is downloaded and enabled from SplunkBase.

D.

When the daleteindex command is executed from the CLI.

Buy Now
Questions 12

The following sample log event shows evidence of credit card numbers being present in the transactions. loc file.

Which of these SEDCM3 settings will mask this and other suspected credit card numbers with an Y character for each character being masked? The indexed event should be formatted as follows:

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 13

What is the recommended method to test the onboarding of a new data source before putting it in production?

Options:

A.

Send test data to a test index.

B.

Send data to the associated production index.

C.

Replicate Splunk deployment in a test environment.

D.

Send data to the chance index.

Buy Now
Questions 14

Which of the following is not considered a best practice for the deployment server?

Options:

A.

Create small, single-purpose deployment apps.

B.

Dedicate a Splunk instance as the deployment server.

C.

Use a Linux server as the deployment server.

D.

Create large, multi-purpose deployment apps.

Buy Now
Questions 15

When using Splunk Universal Forwarders, which of the following is true?

Options:

A.

No more than six Universal Forwarders may connect directly to Splunk Cloud.

B.

Any number of Universal Forwarders may connect directly to Splunk Cloud.

C.

Universal Forwarders must send data to an Intermediate Forwarder.

D.

There must be one Intermediate Forwarder for every three Universal Forwarders.

Buy Now
Questions 16

Where can an administrator download the Splunk Cloud Universal Forwarder credentials package?

Options:

A.

Splunk Support.

B.

Cloud Monitoring Console forwarder drop-down.

C.

Universal Forwarder app in the Splunk Cloud search head.

D.

Splunkbase.

Buy Now
Questions 17

In case of a Change Request, which of the following should submit a support case for Splunk Support?

Options:

A.

The party requesting the change.

B.

Certified Splunk Cloud administrator.

C.

Splunk infrastructure owner.

D.

Any person with the appropriate entitlement

Buy Now
Questions 18

Which of the following is not a path used by Splunk to execute scripts?

Options:

A.

SPLUNK_HOME/etc/system/bin

B.

SPLUNK HOME/etc/appa//bin

C.

SPLUNKHOMS/ctc/scripts/local

D.

SPLUNK_HOME/bin/scripts

Buy Now
Questions 19

Which of the following takes place during the input phase?

Options:

A.

Splunk annotates data with only 3 metadata keys: host, source, and sourcetype.

B.

Splunk sets the character encoding of the data.

C.

Splunk looks at the contents of the data to apply the correct source.

D.

Splunk breaks data into individual lines.

Buy Now
Questions 20

What is the name of the Splunk index that contains the most valuable information for troubleshooting a Splunk issue?

Options:

A.

_internal

B.

lastchanceindex

C.

_monitoring

D.

defaultdb

Buy Now
Questions 21

Which of the following is a valid method to test if a forwarder can successfully send data to Splunk Cloud?

Options:

A.

Search the _audit index to confirm whether the forwarder ID was registered.

B.

Use oneshot from the CLI on the forwarders, then check to see if those logs show up in the Splunk Cloud environment.

C.

On Splunk Cloud UI, click Add Data and upload a test file, then search to see if the logs show up.

D.

Ping the inputssl.example.splunkcloud.com to see if it returns the ping.

Buy Now
Questions 22

Which of the following methods is valid for creating index-time field extractions?

Options:

A.

Use the UI to create a sourcetype, specify the field name and corresponding regular expression with capture statement.

B.

Create a configuration app with the index-time props.conf and/or transfoms. conf, and upload the app via UI.

C.

Use the CU app to define settings in fields.conf, and restart Splunk Cloud.

D.

Use the rex command to extract the desired field, and then save as a calculated field.

Buy Now
Questions 23

In which file can the SH0ULD_LINEMERCE setting be modified?

Options:

A.

transforms.conf

B.

inputs.conf

C.

props.conf

D.

outputs.conf

Buy Now
Questions 24

Which of the following statements is true about data transformations using SEDCMD?

Options:

A.

Can only be used to mask or truncate raw data.

B.

Configured in props.conf and transform.conf.

C.

Can be used to manipulate the sourcetype per event.

D.

Operates on a REGEX pattern match of the source, sourcetype, or host of an event.

Buy Now
Exam Code: SPLK-1005
Exam Name: Splunk Cloud Certified Admin
Last Update: Dec 1, 2024
Questions: 80
$66  $164.99
$50  $124.99
$42  $104.99
buy now SPLK-1005