Which of the following describes a Splunk deployment server?
Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as
follows: 123-44-5678.
Which configuration file and stanza pair will mask possible SSNs in the log events?
Which of the following monitor inputs stanza headers would match all of the following files?
/var/log/www1/secure.log
/var/log/www/secure.l
/var/log/www/logs/secure.logs
/var/log/www2/secure.log
Which Splunk component requires a Forwarder license?
The following stanza is active in indexes.conf:
[cat_facts]
maxHotSpanSecs = 3600
frozenTimePeriodInSecs = 2630000
maxTota1DataSizeMB = 650000
All other related indexes.conf settings are default values.
If the event timestamp was 3739283 seconds ago, will it be searchable?
How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON
A)
B)
C)
D)
An admin oversees an environment with a 1000 GBI day license. The configuration file
server.conf has strict pool quota=false set. The license is divided into the following three pools, and today's usage is shown on the right-hand column:
PoolLicense SizeToday's usage
X500 GB/day100 GB
Y350 GB/day400 GB
Z150 GB/day300 GB
Given this, which pool(s) are issued warnings?
Which of the following is an appropriate description of a deployment server in a non-cluster environment?
Which is a valid stanza for a network input?
Which forwarder is recommended by Splunk to use in a production environment?
A Universal Forwarder is collecting two separate sources of data (A,B). Source A is being routed through a Heavy Forwarder and then to an indexer. Source B is being routed directly to the indexer. Both sets of data require the masking of raw text strings before being written to disk. What does the administrator need to do to
ensure that the masking takes place successfully?
If an update is made to an attribute in inputs.conf on a universal forwarder, on which Splunk component
would the fishbucket need to be reset in order to reindex the data?
A security team needs to ingest a static file for a specific incident. The log file has not been collected previously and future updates to the file must not be indexed.
Which command would meet these needs?
How is a remote monitor input distributed to forwarders?
Which valid bucket types are searchable? (select all that apply)
What is required when adding a native user to Splunk? (select all that apply)
Which of the following are methods for adding inputs in Splunk? (select all that apply)
Which layers are involved in Splunk configuration file layering? (select all that apply)
When running a real-time search, search results are pulled from which Splunk component?
In a distributed environment, which Splunk component is used to distribute apps and configurations to the
other Splunk instances?
What happens when the same username exists in Splunk as well as through LDAP?
What happens when there are conflicting settings within two or more configuration files?
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs
the following search over the last 24 hours:
index=*
What field can the administrator check to see the data distribution?
In which phase of the index time process does the license metering occur?
To set up a Network input in Splunk, what needs to be specified'?
Who provides the Application Secret, Integration, and Secret keys, as well as the API Hostname when setting
up Duo for Multi-Factor Authentication in Splunk Enterprise?
The universal forwarder has which capabilities when sending data? (select all that apply)
The following stanzas in inputs. conf are currently being used by a deployment client:
[udp: //145.175.118.177:1001
Connection_host = dns
sourcetype = syslog
Which of the following statements is true of data that is received via this input?
The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require
multiple indexers. Following best practices, which types of Splunk component instances are needed?
A configuration file in a deployed app needs to be directly edited. Which steps would ensure a successful deployment to clients?
When using a directory monitor input, specific source types can be selectively overridden using which configuration file?
Which Splunk forwarder has a built-in license?
What are the values for host and index for [stanza1] used by Splunk during index time, given the following configuration files?
Running this search in a distributed environment:
On what Splunk component does the eval command get executed?
Which of the methods listed below supports muti-factor authentication?
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
Which of the following is a valid method to create a Splunk user?
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
Syslog files are being monitored on a Heavy Forwarder.
Where would the appropriate TRANSFORMS setting be deployed to reroute logs based on the event message?
What is the difference between the two wildcards ... and - for the monitor stanza in inputs, conf?
Which of the following is valid distribute search group?
A)
B)
C)
D)
What is the valid option for a [monitor] stanza in inputs.conf?
Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?
An index stores its data in buckets. Which default directories does Splunk use to store buckets? (Choose all that apply.)
Which data pipeline phase is the last opportunity for defining event boundaries?
When would the following command be used?
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
Which of the following statements accurately describes using SSL to secure the feed from a forwarder?
In case of a conflict between a whitelist and a blacklist input setting, which one is used?
Which of the following is a valid distributed search group?
After an Enterprise Trial license expires, it will automatically convert to a Free license. How many days is an Enterprise Trial license valid before this conversion occurs?
When deploying apps, which attribute in the forwarder management interface determines the apps that clients install?
When Splunk is integrated with LDAP, which attribute can be changed in the Splunk UI for an LDAP user?
An add-on has configured field aliases for source IP address and destination IP address fields. A specific user prefers not to have those fields present in their user context. Based on the default props.conf below, which SPLUNK_HOME/etc/users/buttercup/myTA/local/props.conf stanza can be added to the user’s local context to disable the field aliases?