Which of the following is true regarding LDAP integration with Splunk Enterprise?
Within props. conf, which stanzas are valid for data modification? (select all that apply)
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?
Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?
Load balancing on a Universal Forwarder is not scaling correctly. The forwarder's outputs. and the tcpout stanza are setup correctly. What else could be the cause of this scaling issue? (select all that apply)
Which setting allows the configuration of Splunk to allow events to span over more than one line?
In this example, ifuseACKis set to true and themaxQueueSizeis set to 7MB, what is the size of the wait queue on this universal forwarder?
Which of the following statements describe deployment management? (select all that apply)
On the deployment server, administrators can map clients to server classes using client filters. Which of the
following statements is accurate?
A Splunk administrator has been tasked with developing a retention strategy to have frequently accessed data sets on SSD storage and to have older, less frequently accessed data on slower NAS storage. They have set a mount point for the NAS. Which parameter do they need to modify to set the path for the older, less frequently accessed data in indexes.conf?
In inputs. conf, which stanza would mean Splunk was only reading one local file?
Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as
follows: 123-44-5678.
Which configuration file and stanza pair will mask possible SSNs in the log events?
A user is assigned two roles with the following search filters. What is the user's applied search filter?
How is data handled by Splunk during the input phase of the data ingestion process?
The following stanza is active in indexes.conf:
[cat_facts]
maxHotSpanSecs = 3600
frozenTimePeriodInSecs = 2630000
maxTota1DataSizeMB = 650000
All other related indexes.conf settings are default values.
If the event timestamp was 3739283 seconds ago, will it be searchable?
Which feature in Splunk allows Event Breaking, Timestamp extractions, and any advanced configurations
found in props.conf to be validated all through the UI?
When working with an indexer cluster, what changes with the global precedence when comparing to a standalone deployment?
Which of the following CLI commands removes a search peer from Distributed Search?
Assume a file is being monitored and the data was incorrectly indexed to an exclusive index. The index is
cleaned and now the data must be reindexed. What other index must be cleaned to reset the input checkpoint
information for that file?
For single line event sourcetypes. it is most efficient to set SHOULD_linemerge to what value?
Which data pipeline phase is the last opportunity for defining event boundaries?
In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?

Event example:
Which file will be matched for the following monitor stanza in inputs. conf?
[monitor: ///var/log/*/bar/*. txt]
When using a directory monitor input, specific source types can be selectively overridden using which configuration file?
Which of the following Splunk components require a separate installation package?
After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?
In a distributed environment, which Splunk component is used to distribute apps and configurations to the
other Splunk instances?
Where should apps be located on the deployment server that the clients pull from?
Which scenario is applicable given the stanzas in authentication.conf below?
[authentication]
externalTwoFactorAuthVendor = Duo
externalTwoFactorAuthSettings = duoMFA
[duoMFA]
integrationKey = aGFwcHliaXJ0aGRheU1pZGR5
secretKey = YXVzdHJhaWxpYW5Gb3JHcmVw
applicationKey = c3BsaW5raW5ndGhlcGx1bWJ1c3NpbmN1OTU
apiHostname = 466993018.duosecurity.com
failOpen = True
timeout = 60
Where can scripts for scripted inputs reside on the host file system? (select all that apply)
After an Enterprise Trial license expires, it will automatically convert to a Free license. How many days is an Enterprise Trial license valid before this conversion occurs?
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
When deploying apps, which attribute in the forwarder management interface determines the apps that clients install?
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
When using a directory monitor input, specific source type can be selectively overridden using which configuration file?
Which of the following is an appropriate description of a deployment server in a non-cluster environment?
In addition to single, non-clustered Splunk instances, what else can the deployment server push apps to?
This file has been manually created on a universal forwarder

A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new

Which file is now monitored?
When configuring monitor inputs with whitelists or blacklists, what is the supported method of filtering the lists?