Which Splunk configuration file is used to enable data integrity checking?
#91
Answer: C✅ Correct❌ Incorrect
An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data is 300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the index?
#92
Answer: C✅ Correct❌ Incorrect
After how many warnings within a rolling 30-day period will a license violation occur with an enforced Enterprise license?
#93
Answer: D✅ Correct❌ Incorrect
Who provides the Application Secret, Integration, and Secret keys, as well as the API Hostname when setting up Duo for Multi-Factor Authentication in Splunk
Enterprise?
#94
Answer: A✅ Correct❌ Incorrect
When does a warm bucket roll over to a cold bucket?
#95
Answer: D✅ Correct❌ Incorrect
If an update is made to an attribute in inputs.conf on a universal forwarder, on which Splunk component would the fishbucket need to be reset in order to reindex the data?
#96
Answer: B✅ Correct❌ Incorrect
Which forwarder type can parse data prior to forwarding?
#97
Answer: D✅ Correct❌ Incorrect
How can native authentication be disabled in Splunk?
#98
Answer: B✅ Correct❌ Incorrect
The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require multiple indexers. Following best practices, which types of
Splunk component instances are needed?
#99
Answer: C✅ Correct❌ Incorrect
Which of the following configuration files are used with a universal forwarder?
#100
Answer: AC✅ Correct❌ Incorrect
Which valid bucket types are searchable?
#101
Answer: ABC✅ Correct❌ Incorrect
How do you remove missing forwarders from the Monitoring Console?
#102
Answer: D✅ Correct❌ Incorrect
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
#103
Answer: A✅ Correct❌ Incorrect
What are the required stanza attributes when configuring the transforms.conf to manipulate or remove events?
#104
Answer: C✅ Correct❌ Incorrect
Which of the following are supported configuration methods to add inputs on a forwarder?
#105
Answer: AB✅ Correct❌ Incorrect
Which of the following enables compression for universal forwarders in outputs.conf?
#106
Answer: B✅ Correct❌ Incorrect
User role inheritance allows what to be inherited from the parent role?
#107
Answer: B✅ Correct❌ Incorrect
Which of the following statements apply to directory inputs?
#108
Answer: A✅ Correct❌ Incorrect
How would you configure your distsearch.conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_server_group=HOUSTON
#109
Answer: C✅ Correct❌ Incorrect
Which of the following is a valid distributed search group?
#110
Answer: D✅ Correct❌ Incorrect
Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?
#111
Answer: C✅ Correct❌ Incorrect
A new forwarder has been installed with a manually created deploymentclient.conf.
What is the next step to enable the communication between the forwarder and the deployment server?
#112
Answer: C✅ Correct❌ Incorrect
When using a directory monitor input, specific source type can be selectively overridden using which configuration file?
#113
Answer: A✅ Correct❌ Incorrect
When using license pools, volume allocations apply to which Splunk components?
#114
Answer: A✅ Correct❌ Incorrect
An add-on has configured field aliases for source IP address and destination IP address fields. A specific user prefers not to have those fields present in their user context. Based on the default props.conf below, which SPLUNK_HOME/etc/users/buttercup/myTA/local/props.conf stanza can be added to the user’s local context to disable the field aliases?
#115
Answer: B✅ Correct❌ Incorrect
Which of the following are methods for adding inputs in Splunk?
#116
Answer: AB✅ Correct❌ Incorrect
Which of the following authentication types requires scripting in Splunk?
#117
Answer: D✅ Correct❌ Incorrect
Which option accurately describes the purpose of the HTTP Event Collector (HEC)?
#118
Answer: B✅ Correct❌ Incorrect
What is the difference between the two wildcards ... and * for the monitor stanza in inputs.conf?
#119
Answer: C✅ Correct❌ Incorrect
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?