Exam 4: Splunk Enterprise Certified Architect

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

Place content to set on page load inside which of the following Simple XML tags?

Free
(Multiple Choice)
4.8/5
(41)
Correct Answer:
Verified

C

Which of the following is an example of a Splunk KV store use case? (Select all that apply.)

Free
(Multiple Choice)
4.9/5
(32)
Correct Answer:
Verified

A,B

Suppose the following query in a Simple XML dashboard returns a table including hyperlinks: <search>       <query>index news sourcetype web_proxy | table sourcetype title link       </query> </search> Which of the following is a valid dynamic drilldown element to allow a user of the dashboard to visit the hyperlinks contained in the link field?

Free
(Multiple Choice)
4.8/5
(35)
Correct Answer:
Verified

A

Which of the following are valid parent elements for the event action shown below? (Select all that apply.) <set token=" Token Name ">sourcetype=$click.value|s$</set>

(Multiple Choice)
4.7/5
(36)

How can event logs be collected from a remote Windows machine using a standard Splunk installation and no customization? (Select all that apply.)

(Multiple Choice)
4.7/5
(29)

Which Splunk REST endpoint is used to create a KV store collection?

(Multiple Choice)
4.8/5
(41)

There is a global search named "global_search" defined on a form as shown below: <search id="global_search">    <query>    index-_internal source-*splunkd.log | stats count by component, log_level    </query> </search> Which of the following would be a valid post-processing search? (Select all that apply.)

(Multiple Choice)
4.9/5
(34)

Using Splunk Web to modify config settings for a shared object, a revised file with those changes is placed in which directory?

(Multiple Choice)
4.9/5
(35)

What predefined drilldown tokens are available specifically for trellis layouts? (Select all that apply.)

(Multiple Choice)
4.8/5
(43)

Which of the following endpoints is used to authenticate with the Splunk REST API?

(Multiple Choice)
4.8/5
(36)

In order to successfully accelerate a report, which criteria must the search meet? (Select all that apply.)

(Multiple Choice)
4.7/5
(37)

Which of the following are reserved field names in a KV Store? (Select all that apply.)

(Multiple Choice)
4.9/5
(35)

How can indexer acknowledgement be enabled for HTTP Event Collector (HEC)? (Select all that apply.)

(Multiple Choice)
4.8/5
(26)

In a DELETE request, what would omitting the value of _key from the REST endpoint do?

(Multiple Choice)
4.9/5
(35)

Which of the following are requirements for arguments sent to the data/indexes endpoint? (Select all that apply.)

(Multiple Choice)
4.8/5
(41)

Assuming permissions are set appropriately, which REST endpoint path can be used by someone with a power user role to access information about mySearch, a saved search owned by someone with a user role?

(Multiple Choice)
4.9/5
(34)

Which of the following are ways to get a list of search jobs? (Select all that apply.)

(Multiple Choice)
4.8/5
(37)

A fellow Splunk administrator is reviewing an app that has been downloaded from splunkbase and deployed in an organization. The admin has e-mailed the following configuration snippet with a brief note that says "fix the permissions". In what configuration file should the snippet be placed? [] access = read : [ * ], write : [ admin ] export - system (Assume that $APP_HOME refers to the path that the app is installed, e.g. $SPLUNK_HOME/etc/apps/ <app name> )

(Multiple Choice)
4.9/5
(32)

Which of the following is true of a namespace?

(Multiple Choice)
4.8/5
(30)

The response message from a successful Splunk REST call includes an <entry> element. What is contained in an element?

(Multiple Choice)
4.9/5
(32)
Showing 1 - 20 of 42
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)