Load balancing on a Universal Forwarder is not scaling correctly. The forwarder's outputs. and the tcpout stanza are setup correctly. What else could be the cause of this scaling issue? (select all that apply)
How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON
A)
B)
C)
D)
A configuration file in a deployed app needs to be directly edited. Which steps would ensure a successful deployment to clients?
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
When running the command shown below, what is the default path in which deployment server. conf is created?
splunk set deploy-poll deployServer:port
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
You update a props. conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btoo1 props list —debug. What will the output be?
Which default Splunk role could be assigned to provide users with the following capabilities?
Create saved searches
Edit shared objects and alerts
Not allowed to create custom roles
Which Splunk component distributes apps and certain other configuration updates to search head cluster members?
A Splunk administrator has been tasked with developing a retention strategy to have frequently accessed data sets on SSD storage and to have older, less frequently accessed data on slower NAS storage. They have set a mount point for the NAS. Which parameter do they need to modify to set the path for the older, less frequently accessed data in indexes.conf?
The following stanza is active in indexes.conf:
[cat_facts]
maxHotSpanSecs = 3600
frozenTimePeriodInSecs = 2630000
maxTota1DataSizeMB = 650000
All other related indexes.conf settings are default values.
If the event timestamp was 3739283 seconds ago, will it be searchable?
Which of the following are methods for adding inputs in Splunk? (select all that apply)
Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?
Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?
What is the difference between the two wildcards ... and - for the monitor stanza in inputs, conf?
Which of the following enables compression for universal forwarders in outputs. conf ?
A)
B)
C)
D)
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs
the following search over the last 24 hours:
index=*
What field can the administrator check to see the data distribution?
An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data
is 300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the
index?
What event-processing pipelines are used to process data for indexing? (select all that apply)
Which of the following Splunk components require a separate installation package?
Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)
User role inheritance allows what to be inherited from the parent role? (select all that apply)
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
Syslog files are being monitored on a Heavy Forwarder.
Where would the appropriate TRANSFORMS setting be deployed to reroute logs based on the event message?
What are the values forhostandindexfor[stanza1]used by Splunk during index time, given the following configuration files?
Which of the following monitor inputs stanza headers would match all of the following files?
/var/log/www1/secure.log
/var/log/www/secure.l
/var/log/www/logs/secure.logs
/var/log/www2/secure.log
Which Splunk component would one use to perform line breaking prior to indexing?
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?
An add-on has configured field aliases for source IP address and destination IP address fields. A specific user prefers not to have those fields present in their user context. Based on the defaultprops.confbelow, whichSPLUNK_HOME/etc/users/buttercup/myTA/local/props.confstanza can be added to the user’s local context to disable the field aliases?
Which optional configuration setting in inputs .conf allows you to selectively forward the data to specific indexer(s)?
Which of the following indexes come pre-configured with Splunk Enterprise? (select all that apply)