Splunk SPLK-1003 Splunk Enterprise Certified Admin Exam Practice Test
Splunk Enterprise Certified Admin Questions and Answers
Which Splunk component would one use to perform line breaking prior to indexing?
Which options for Multifactor Authentication, also known as MFA, are available in Splunk Enterprise?
After an Enterprise Trial license expires, it will automatically convert to a Free license. How many days is an Enterprise Trial license valid before this conversion occurs?
Which of the following authentication types requires scripting in Splunk?
Data from a monitored file was accidentally indexed into Index B, but it should have been indexed into Index A. Which set of steps correctly fixes the issue and allows the data to be re-indexed into the correct index?
An admin oversees an environment with a 1000 GBI day license. The configuration file
server.conf has strict pool quota=false set. The license is divided into the following three pools, and today ' s usage is shown on the right-hand column:
PoolLicense SizeToday ' s usage
X500 GB/day100 GB
Y350 GB/day400 GB
Z150 GB/day300 GB
Given this, which pool(s) are issued warnings?
After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?
A configuration file in a deployed app needs to be directly edited. Which steps would ensure a successful deployment to clients?
What happens when the same username exists in Splunk as well as through LDAP?
Which configuration accepts syslog data over UDP port 514 from all 10.x.x.x hosts except hosts in the 10.1.x.x network?
Which Splunk component performs indexing and responds to search requests from the search head?
What is the default purpose of a Splunk Deployment Server?
Which of the following are available input methods when adding a file input in Splunk Web? (Choose all that
apply.)
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
Which forwarder is recommended by Splunk to use in a production environment?
What is the valid option for a [monitor] stanza in inputs.conf?
Which additional component is required for a search head cluster?
Which default Splunk role could be assigned to provide users with the following capabilities?
Create saved searches
Edit shared objects and alerts
Not allowed to create custom roles
Which of the following are methods for adding inputs in Splunk? (select all that apply)
Which valid bucket types are searchable? (select all that apply)
On the deployment server, administrators can map clients to server classes using client filters. Which of the
following statements is accurate?
Windows can prevent a Splunk forwarder from reading open files. If files need to be read while they are being written to, what type of input stanza needs to be created?
The universal forwarder has which capabilities when sending data? (select all that apply)
Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?
Which parent directory contains the configuration files in Splunk?
When are knowledge bundles distributed to search peers?
What event-processing pipelines are used to process data for indexing? (select all that apply)
Which option on the Add Data menu is most useful for testing data ingestion without creating inputs.conf?
What is the default purpose of a Splunk Deployment Server ?
Which of the following is an acceptable channel value when using the HTTP Event Collector indexer acknowledgment capability?
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?
When working with an indexer cluster, what changes with the global precedence when comparing to a standalone deployment?
Which setting allows the configuration of Splunk to allow events to span over more than one line?
Which Splunk component does a search head primarily communicate with?
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs
the following search over the last 24 hours:
index=*
What field can the administrator check to see the data distribution?
After how many warnings within a rolling 30-day period will a license violation occur with an enforced
Enterprise license?
The priority of layered Splunk configuration files depends on the file ' s:
What action could be taken to prevent a license warning with an ingest-based license?
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
How do you remove missing forwarders from the Monitoring Console?
What is the correct curl to send multiple events through HTTP Event Collector?
A log file contains 193 days worth of timestamped events. Which monitor stanza would be used to collect data 45 days old and newer from that log file?
An add-on has configured field aliases for source IP address and destination IP address fields. A specific user prefers not to have those fields present in their user context. Based on the defaultprops.confbelow, whichSPLUNK_HOME/etc/users/buttercup/myTA/local/props.confstanza can be added to the user’s local context to disable the field aliases?

Which of the following indexes come pre-configured with Splunk Enterprise? (select all that apply)
Which of the following apply to how distributed search works? (select all that apply)
What options are available when creating custom roles? (select all that apply)
Which Splunk forwarder has a built-in license?
This file has been manually created on a universal forwarder
A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new

Which file is now monitored?
Which of the following are reasons to create separate indexes? (Choose all that apply.)
Which option accurately describes the purpose of the HTTP Event Collector (HEC)?
Where should apps be located on the deployment server that the clients pull from?
Which of the following CLI commands removes a search peer from Distributed Search?
In which phase of the index time process does the license metering occur?
Which of the following accurately describes HTTP Event Collector indexer acknowledgement?
What is the correct attribute to set in inputs.conf in order to have data sent to a particular indexer group?
What conf file needs to be edited to set up distributed search groups?
Which of the following are supported options when configuring optional network inputs?
Which Splunk component distributes apps and certain other configuration updates to search head cluster members?
In addition to single, non-clustered Splunk instances, what else can the deployment server push apps to?
A Universal Forwarder is monitoring a very active syslog stream and as a result is unable to switch between destinations. How would an admin safely remediate this issue?
When indexing a data source, which fields are considered metadata?
Which of the methods listed below supports muti-factor authentication?
When deploying apps on Universal Forwarders using the deployment server, what is the correct component and location of the app before it is deployed?