Which of the following apply to how distributed search works? (select all that apply)
Which Splunk configuration file is used to enable data integrity checking?
Windows can prevent a Splunk forwarder from reading open files. If files need to be read while they are being written to, what type of input stanza needs to be created?
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
Which of the following is the recommended guideline for creating a new user role?
Syslog files are being monitored on a Heavy Forwarder.
Where would the appropriate TRANSFORMS setting be deployed to reroute logs based on the event message?
Which default Splunk role could be assigned to provide users with the following capabilities?
Create saved searches
Edit shared objects and alerts
Not allowed to create custom roles
What is the default character encoding used by Splunk during the input phase?
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)
The following stanzas in inputs. conf are currently being used by a deployment client:
[udp: //145.175.118.177:1001
Connection_host = dns
sourcetype = syslog
Which of the following statements is true of data that is received via this input?
What is required when adding a native user to Splunk? (select all that apply)
Where should apps be located on the deployment server that the clients pull from?
Which Splunk component requires a Forwarder license?
What is the correct example to redact a plain-text password from raw events?
When Splunk is integrated with LDAP, which attribute can be changed in the Splunk UI for an LDAP user?
Which of the following enables compression for universal forwarders in outputs. conf ?
A)

B)

C)

D)

Which of the following is a valid distributed search group?
Which of the following types of data count against the license daily quota?
An add-on has configured field aliases for source IP address and destination IP address fields. A specific user prefers not to have those fields present in their user context. Based on the defaultprops.confbelow, whichSPLUNK_HOME/etc/users/buttercup/myTA/local/props.confstanza can be added to the user’s local context to disable the field aliases?


Which forwarder type can parse data prior to forwarding?
When using a directory monitor input, specific source type can be selectively overridden using which configuration file?
What happens when the same username exists in Splunk as well as through LDAP?
How is a remote monitor input distributed to forwarders?
Which valid bucket types are searchable? (select all that apply)
A non-clustered Splunk environment has three indexers (A,B,C) and two search heads (X, Y). During a search executed on search head X, indexer A crashes. What is Splunk's response?
Seven different network switches are sending traffic to a server hosting a Universal Forwarder. Three of the devices are sending TCP data and four of the devices are sending UDP data.
What is the minimum number of input stanzas that must be created on the Universal Forwarder to successfully capture data from all seven sources?
What is the correct curl to send multiple events through HTTP Event Collector?
Within props. conf, which stanzas are valid for data modification? (select all that apply)
Which of the following is a benefit of distributed search?
What is the command to reset the fishbucket for one source?
The priority of layered Splunk configuration files depends on the file's:
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
TheLINE_BREAKERattribute is configured in which configuration file?
Which option on the Add Data menu is most useful for testing data ingestion without creating inputs.conf?
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
What action is required to enable forwarder management in Splunk Web?
Which of the following must be done to define user permissions when integrating Splunk with LDAP?
On the deployment server, administrators can map clients to server classes using client filters. Which of the
following statements is accurate?
An index stores its data in buckets. Which default directories does Splunk use to store buckets? (Choose all that apply.)
What is the importance of modifying Transparent Huge Pages (THP) and ulimit settings when installing Splunk Enterprise?
In inputs. conf, which stanza would mean Splunk was only reading one local file?
In which Splunk configuration is the SEDCMD used?
Search heads in a company's European offices need to be able to search data in their New York offices. They also need to restrict access to certain indexers. What should be configured to allow this type of action?
Which of the following statements describes how distributed search works?
Which of the following is accurate regarding the input phase?
Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as
follows: 123-44-5678.
Which configuration file and stanza pair will mask possible SSNs in the log events?
Which of the methods listed below supports muti-factor authentication?
What happens when there are conflicting settings within two or more configuration files?
What will the following inputs. conf stanza do?
[script://myscript . sh]
Interval=0
What is the correct order of steps in Duo Multifactor Authentication?
What is the name of the object that stores events inside of an index?
What is the valid option for a [monitor] stanza in inputs.conf?
What is a role in Splunk? (select all that apply)
During search time, which directory of configuration files has the highest precedence?
Which Splunk forwarder has a built-in license?
When does a warm bucket roll over to a cold bucket?
The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require
multiple indexers. Following best practices, which types of Splunk component instances are needed?
A company moves to a distributed architecture to meet the growing demand for the use of Splunk. What parameter can be configured to enable automatic load balancing in the
Universal Forwarder to send data to the indexers?
What conf file needs to be edited to set up distributed search groups?