Which option on the Add Data menu is most useful for testing data ingestion without creating inputs.conf?
What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?
When using license pools, volume allocations apply to which Splunk components?
Which of the following are supported configuration methods to add inputs on a forwarder? (select all that apply)
In which phase do indexed extractions in props.conf occur?
Which of the following must be done to define user permissions when integrating Splunk with LDAP?
What is required when adding a native user to Splunk? (select all that apply)
How is a remote monitor input distributed to forwarders?
What action is required to enable forwarder management in Splunk Web?
Which scenario is applicable given the stanzas in authentication.conf below?
[authentication]
externalTwoFactorAuthVendor = Duo
externalTwoFactorAuthSettings = duoMFA
[duoMFA]
integrationKey = aGFwcHliaXJ0aGRheU1pZGR5
secretKey = YXVzdHJhaWxpYW5Gb3JHcmVw
applicationKey = c3BsaW5raW5ndGhlcGx1bWJ1c3NpbmN1OTU
apiHostname = 466993018.duosecurity.com
failOpen = True
timeout = 60
Event processing occurs at which phase of the data pipeline?
Which is a valid stanza for a network input?
When deploying apps on Universal Forwarders using the deployment server, what is the correct component and location of the app before it is deployed?
When should the Data Preview feature be used?
When would the following command be used?
To set up a Network input in Splunk, what needs to be specified'?
What is the command to reset the fishbucket for one source?
What is the name of the object that stores events inside of an index?
After an Enterprise Trial license expires, it will automatically convert to a Free license. How many days is an Enterprise Trial license valid before this conversion occurs?
An admin oversees an environment with a 1000 GBI day license. The configuration file
server.conf has strict pool quota=false set. The license is divided into the following three pools, and today's usage is shown on the right-hand column:
PoolLicense SizeToday's usage
X500 GB/day100 GB
Y350 GB/day400 GB
Z150 GB/day300 GB
Given this, which pool(s) are issued warnings?
In inputs. conf, which stanza would mean Splunk was only reading one local file?
Using SEDCMD in props.conf allows raw data to be modified. With the given event below, which option will mask the first three digits of the AcctID field resulting output: [22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Event:
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Which of the following types of data count against the license daily quota?
On the deployment server, administrators can map clients to server classes using client filters. Which of the
following statements is accurate?
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
Load balancing on a Universal Forwarder is not scaling correctly. The forwarder's outputs. and the tcpout stanza are setup correctly. What else could be the cause of this scaling issue? (select all that apply)
User role inheritance allows what to be inherited from the parent role? (select all that apply)
A Universal Forwarder has the following active stanza in inputs . conf:
[monitor: //var/log]
disabled = O
host = 460352847
An event from this input has a timestamp of 10:55. What timezone will Splunk add to the event as part of indexing?
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
Which of the following authentication types requires scripting in Splunk?
When does a warm bucket roll over to a cold bucket?
You update a props. conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btoo1 props list —debug. What will the output be?
Within props. conf, which stanzas are valid for data modification? (select all that apply)
Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?
How does the Monitoring Console monitor forwarders?
Which file will be matched for the following monitor stanza in inputs. conf?
[monitor: ///var/log/*/bar/*. txt]
When running a real-time search, search results are pulled from which Splunk component?
Search heads in a company's European offices need to be able to search data in their New York offices. They also need to restrict access to certain indexers. What should be configured to allow this type of action?
Which Splunk component requires a Forwarder license?
Which data pipeline phase is the last opportunity for defining event boundaries?
A Universal Forwarder is collecting two separate sources of data (A,B). Source A is being routed through a Heavy Forwarder and then to an indexer. Source B is being routed directly to the indexer. Both sets of data require the masking of raw text strings before being written to disk. What does the administrator need to do to
ensure that the masking takes place successfully?
Syslog files are being monitored on a Heavy Forwarder.
Where would the appropriate TRANSFORMS setting be deployed to reroute logs based on the event message?
A security team needs to ingest a static file for a specific incident. The log file has not been collected previously and future updates to the file must not be indexed.
Which command would meet these needs?
What is the difference between the two wildcards ... and - for the monitor stanza in inputs, conf?
After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs
the following search over the last 24 hours:
index=*
What field can the administrator check to see the data distribution?
Which Splunk component performs indexing and responds to search requests from the search head?
Who provides the Application Secret, Integration, and Secret keys, as well as the API Hostname when setting
up Duo for Multi-Factor Authentication in Splunk Enterprise?
Immediately after installation, what will a Universal Forwarder do first?
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?
All search-time field extractions should be specified on which Splunk component?
In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?
Event example:
What options are available when creating custom roles? (select all that apply)
When are knowledge bundles distributed to search peers?