Free Certification Practice Questions

SPLUNK-SPLK-1003

Loading…
On the deployment server, administrators can map clients to server classes using client filters. Which of the following statements is accurate?
#151
Which configuration file would be used to forward the Splunk internal logs from a search head to the indexer?
#152
When configuring HTTP Event Collector (HEC) input, how would one ensure the events have been indexed?
#153
What is the valid option for a [monitor] stanza in inputs.conf?
#154
Which of the following is a benefit of distributed search?
#155
The CLI command splunk add forward-server indexer:<receiving-port> will create stanza(s) in which configuration file?
#156
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs the following search over the last 24 hours: index=* What field can the administrator check to see the data distribution?
#157
Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
#158
Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as follows: 123-44-5678. Which configuration file and stanza pair will mask possible SSNs in the log events?
#159
Where are deployment server apps mapped to clients?
#160
Which of the following statements accurately describes using SSL to secure the feed from a forwarder?
#161
Which feature of Splunk's role configuration can be used to aggregate multiple roles intended for groups of users?
#162
Which of the following is the use case for the deployment server feature of Splunk?
#163
When running a real-time search, search results are pulled from which Splunk component?
#164
A sourcetype has been explicitly set in inputs.conf. How can the sourcetype be fine-tuned in props.conf during the Input phase?
#165
Which of these is not a valid way to get data into Splunk?
#166
When configuring Distributed Search, which of the following stanzas will add search peers?
#167
What is the correct order of index time precedence? (For each of the following, highest precedence is shown at the top and lowest precedence is shown at the bottom)
#168
Which Splunk component requires a Forwarder license?
#169