Exam 3: Splunk Certified Developer

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

What are the minimum required settings when creating a network input in Splunk?

Free
(Multiple Choice)
4.8/5
(24)
Correct Answer:
Verified

A

The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs the following search over the last 24 hours: index=* What field can the administrator check to see the data distribution?

Free
(Multiple Choice)
4.9/5
(34)
Correct Answer:
Verified

D

With authentication methods are natively supported within Splunk Enterprise? (Choose all that apply.)

Free
(Multiple Choice)
4.8/5
(40)
Correct Answer:
Verified

A,D

Which of the following configuration files are used with a universal forwarder? (Choose all that apply.)

(Multiple Choice)
4.9/5
(47)

Which option accurately describes the purpose of the HTTP Event Collector (HEC)?

(Multiple Choice)
4.8/5
(31)

The universal forwarder has which capabilities when sending data? (Select all that apply.)

(Multiple Choice)
4.9/5
(43)

On the deployment server, administrators can map clients to server classes using client filters. Which of the following statements is accurate?

(Multiple Choice)
4.8/5
(41)

Where are license files stored?

(Multiple Choice)
4.9/5
(30)

Which of the following are methods for adding inputs in Splunk? (Select all that apply.)

(Multiple Choice)
4.8/5
(37)

How can native authentication be disabled in Splunk?

(Multiple Choice)
4.8/5
(43)

How would you configure your distsearch.conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_server_group=HOUSTON

(Multiple Choice)
4.8/5
(32)

Which is a valid stanza for a network input?

(Multiple Choice)
4.9/5
(42)

Which setting in indexes.conf allows data retention to be controlled by time?

(Multiple Choice)
4.8/5
(37)

Within props.conf , which stanzas are valid for data modification? (Choose all that apply.)

(Multiple Choice)
4.8/5
(41)

Which of the following statements describe deployment management? (Select all that apply.)

(Multiple Choice)
4.9/5
(47)

The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require multiple indexers. Following best practices, which types of Splunk component instances are needed?

(Multiple Choice)
4.8/5
(31)

Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)

(Multiple Choice)
4.7/5
(25)

What is required when adding a native user to Splunk? (Choose all that apply.)

(Multiple Choice)
4.8/5
(30)

The universal forwarder has which capabilities when sending data? (Choose all that apply.)

(Multiple Choice)
4.9/5
(45)

This file has been manually created on a universal forwarder: /opt/splunkforwarder/etc/apps/my_TA/local/inputs.conf [monitor:///var/log/messages] sourcetype=syslog index=syslog A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new inputs.conf file: /opt/splunk/etc/deployment-apps/my_TA/local/inputs.conf [monitor:///var/log/maillog] sourcetype=maillog Which file is now monitored?

(Multiple Choice)
4.8/5
(39)
Showing 1 - 20 of 84
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)