When running the command shown below, what is the default path in which deploymentserver.conf is created? splunk set deploy-poll deployServer:port
#31
Answer: B✅ Correct❌ Incorrect
Which of the following are valid methods to create a Splunk user?
#32
Answer: ACD✅ Correct❌ Incorrect
What is a role in Splunk?
#33
Answer: BC✅ Correct❌ Incorrect
Which of the following describes a Splunk deployment server?
#34
Answer: D✅ Correct❌ Incorrect
Multi-factor authentication works with which of the following?
#35
Answer: BCD✅ Correct❌ Incorrect
An index stores its data in buckets. Which default directories does Splunk use to store buckets?
#36
Answer: CD✅ Correct❌ Incorrect
The LINE_BREAKER attribute is configured in which configuration file?
#37
Answer: A✅ Correct❌ Incorrect
This file has been manually created on a universal forwarder:
/opt/splunkforwarder/etc/apps/my_TA/local/inputs.conf
[monitor:///var/log/messages]
sourcetype=syslog
index=syslog
A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new inputs.conf file:
/opt/splunk/etc/deployment-apps/my_TA/local/inputs.conf
[monitor:///var/log/maillog]
sourcetype=maillog
index=syslog
Which file is now monitored?
#38
Answer: B✅ Correct❌ Incorrect
After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?
#39
Answer: C✅ Correct❌ Incorrect
A log file contains 193 days worth of timestamped events. Which monitor stanza would be used to collect data 45 days old and newer from that log file?
#40
Answer: D✅ Correct❌ Incorrect
What is the command to reset the fishbucket for one source?
#41
Answer: C✅ Correct❌ Incorrect
Which setting allows the configuration of Splunk to allow events to span over more than one line?
#42
Answer: A✅ Correct❌ Incorrect
In this example, if useACK is set to true and the maxQueueSize is set to 7MB, what is the size of the wait queue on this universal forwarder?
#43
Answer: A✅ Correct❌ Incorrect
Which of the following are reasons to create separate indexes?
#44
Answer: AC✅ Correct❌ Incorrect
You update a props.conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btool props list `"-debug. What will the output be?
#45
Answer: C✅ Correct❌ Incorrect
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
#46
Answer: B✅ Correct❌ Incorrect
Which of the following must be done to define user permissions when integrating Splunk with LDAP?
#47
Answer: B✅ Correct❌ Incorrect
In which phase do indexed extractions in props.conf occur?
#48
Answer: A✅ Correct❌ Incorrect
Which of the following statements describes how distributed search works?
#49
Answer: C✅ Correct❌ Incorrect
Which feature in Splunk allows Event Breaking, Timestamp extractions, and any advanced configurations found in props.conf to be validated all through the UI?
#50
Answer: C✅ Correct❌ Incorrect
What is the correct curl to send multiple events through HTTP Event Collector?
#51
Answer: B✅ Correct❌ Incorrect
The priority of layered Splunk configuration files depends on the file's:
#52
Answer: C✅ Correct❌ Incorrect
Which of the following methods will connect a deployment client to a deployment server?
#53
Answer: D✅ Correct❌ Incorrect
What is the supported compatibility between search heads and search peers?
#54
Answer: C✅ Correct❌ Incorrect
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
#55
Answer: C✅ Correct❌ Incorrect
After an Enterprise Trial license expires, it will automatically convert to a Free license. How many days is an Enterprise Trial license valid before this conversion occurs?
#56
Answer: B✅ Correct❌ Incorrect
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?
#57
Answer: D✅ Correct❌ Incorrect
Which of the following is an appropriate description of a deployment server in a non-cluster environment?
#58
Answer: B✅ Correct❌ Incorrect
Which Splunk forwarder has a built-in license?
#59
Answer: C✅ Correct❌ Incorrect
What happens when the same username exists in Splunk as well as through LDAP?