Exam 7: Splunk Core Certified Consultant

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

A Splunk Index cluster is being installed and the indexers need to be configured with a license master. After the customer provides the name of the license master, what is the next step?

(Multiple Choice)
4.8/5
(47)

Consider the search shown below. Consider the search shown below.   What is this search's intended function? What is this search's intended function?

(Multiple Choice)
4.9/5
(35)

A customer would like to remove the output_file capability from users with the default user role to stop them from filling up the disk on the search head with lookup files. What is the best way to remove this capability from users?

(Multiple Choice)
4.7/5
(39)

Which of the following server.conf stanzas indicates the Indexer Discovery feature has not been fully configured (restart pending) on the Master Node?

(Multiple Choice)
4.7/5
(29)

A customer has asked for a five-node search head cluster (SHC), but does not have the storage budget to use a replication factor greater than 2. They would like to understand what might happen in terms of the users' ability to view historic scheduled search results if they log onto a search head which doesn't contain one of the 2 copies of a given search artifact. Which of the following statements best describes what would happen in this scenario?

(Multiple Choice)
4.8/5
(42)

A customer is using regex to whitelist access logs and secure logs from a web server, but only the access logs are being ingested. Which troubleshooting resource would provide insight into why the secure logs are not being ingested?

(Multiple Choice)
4.8/5
(41)

The customer wants to migrate their current Splunk Index cluster to new hardware to improve indexing and search performance. What is the correct process and procedure for this task?

(Multiple Choice)
4.8/5
(27)

What happens to the indexer cluster when the indexer Cluster Master (CM) runs out of disk space?

(Multiple Choice)
4.9/5
(30)

When setting up a multisite search head and indexer cluster, which nodes are required to declare site membership?

(Multiple Choice)
4.8/5
(34)

A customer has a number of inefficient regex replacement transforms being applied. When under heavy load the indexers are struggling to maintain the expected indexing rate. In a worst case scenario, which queue(s) would be expected to fill up?

(Multiple Choice)
4.7/5
(23)

A customer has been using Splunk for one year, utilizing a single/all-in-one instance. This single Splunk server is now struggling to cope with the daily ingest rate. Also, Splunk has become a vital system in day-to-day operations making high availability a consideration for the Splunk service. The customer is unsure how to design the new environment topology in order to provide this. Which resource would help the customer gather the requirements for their new architecture?

(Multiple Choice)
4.9/5
(39)

When monitoring and forwarding events collected from a file containing unstructured textual events, what is the difference in the Splunk2Splunk payload traffic sent between a universal forwarder (UF) and indexer compared to the Splunk2Splunk payload sent between a heavy forwarder (HF) and the indexer layer? (Assume that the file is being monitored locally on the forwarder.)

(Multiple Choice)
4.7/5
(37)

Consider the scenario where the /var/log directory contains the files secure, messages, cron, audit . A customer has created the following inputs.conf stanzas in the same Splunk app in order to attempt to monitor the files secure and messages : Consider the scenario where the /var/log directory contains the files secure, messages, cron, audit . A customer has created the following inputs.conf stanzas in the same Splunk app in order to attempt to monitor the files secure and messages :   Which file(s) will actually be actively monitored? Which file(s) will actually be actively monitored?

(Multiple Choice)
5.0/5
(34)

When utilizing a subsearch within a Splunk SPL search query, which of the following statements is accurate?

(Multiple Choice)
4.9/5
(39)

An index receives approximately 50GB of data per day per indexer at an even and consistent rate. The customer would like to keep this data searchable for a minimum of 30 days. In addition, they have hourly scheduled searches that process a week's worth of data and are quite sensitive to search performance. Given ideal conditions (no restarts, nor drops/bursts in data volume), and following PS best practices, which of the following sets of indexes.conf settings can be leveraged to meet the requirements?

(Multiple Choice)
4.8/5
(40)

Which statement is true about subsearches?

(Multiple Choice)
4.8/5
(32)

What is the primary driver behind implementing indexer clustering in a customer's environment?

(Multiple Choice)
4.9/5
(48)

Which of the following processor occur in the indexing pipeline?

(Multiple Choice)
4.9/5
(39)

A customer has a network device that transmits logs directly with UDP or TCP over SSL. Using PS best practices, which ingestion method should be used?

(Multiple Choice)
4.8/5
(43)

A [script://] input sends data to a Splunk forwarder using which method?

(Multiple Choice)
4.8/5
(35)
Showing 21 - 40 of 62
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)