Exam 5: Splunk Enterprise Security Certified Admin

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

Which of the following describe migration from single-site to multisite index replication?

(Multiple Choice)
4.7/5
(33)

Indexing is slow and real-time search results are delayed in a Splunk environment with two indexers and one search head. There is ample CPU and memory available on the indexers. Which of the following is most likely to improve indexing performance?

(Multiple Choice)
4.9/5
(33)

A new Splunk customer is using syslog to collect data from their network devices on port 514. What is the best practice for ingesting this data into Splunk?

(Multiple Choice)
4.9/5
(36)

What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza?

(Multiple Choice)
4.8/5
(37)

A Splunk architect has inherited the Splunk deployment at Buttercup Games and end users are complaining that the events are inconsistently formatted for a web sourcetype. Further investigation reveals that not all web logs flow through the same infrastructure: some of the data goes through heavy forwarders and some of the forwarders are managed by another department. Which of the following items might be the cause for this issue?

(Multiple Choice)
4.8/5
(44)
Showing 81 - 85 of 85
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)