Free Certification Practice Questions

SPLUNK-SPLK-1003

Loading…
Which Splunk configuration file is used to enable data integrity checking?
#91
An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data is 300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the index?
#92
After how many warnings within a rolling 30-day period will a license violation occur with an enforced Enterprise license?
#93
Who provides the Application Secret, Integration, and Secret keys, as well as the API Hostname when setting up Duo for Multi-Factor Authentication in Splunk Enterprise?
#94
When does a warm bucket roll over to a cold bucket?
#95
If an update is made to an attribute in inputs.conf on a universal forwarder, on which Splunk component would the fishbucket need to be reset in order to reindex the data?
#96
Which forwarder type can parse data prior to forwarding?
#97
How can native authentication be disabled in Splunk?
#98
The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require multiple indexers. Following best practices, which types of Splunk component instances are needed?
#99
Which of the following configuration files are used with a universal forwarder?
#100
Which valid bucket types are searchable?
#101
How do you remove missing forwarders from the Monitoring Console?
#102
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
#103
What are the required stanza attributes when configuring the transforms.conf to manipulate or remove events?
#104
Which of the following are supported configuration methods to add inputs on a forwarder?
#105
Which of the following enables compression for universal forwarders in outputs.conf?
#106
User role inheritance allows what to be inherited from the parent role?
#107
Which of the following statements apply to directory inputs?
#108
How would you configure your distsearch.conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_server_group=HOUSTON
#109
Which of the following is a valid distributed search group?
#110
Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?
#111
A new forwarder has been installed with a manually created deploymentclient.conf. What is the next step to enable the communication between the forwarder and the deployment server?
#112
When using a directory monitor input, specific source type can be selectively overridden using which configuration file?
#113
When using license pools, volume allocations apply to which Splunk components?
#114
An add-on has configured field aliases for source IP address and destination IP address fields. A specific user prefers not to have those fields present in their user context. Based on the default props.conf below, which SPLUNK_HOME/etc/users/buttercup/myTA/local/props.conf stanza can be added to the user’s local context to disable the field aliases?
#115
Question image
Which of the following are methods for adding inputs in Splunk?
#116
Which of the following authentication types requires scripting in Splunk?
#117
Which option accurately describes the purpose of the HTTP Event Collector (HEC)?
#118
What is the difference between the two wildcards ... and * for the monitor stanza in inputs.conf?
#119
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
#120