Which Splunk component would one use to perform line breaking prior to indexing?
In inputs. conf, which stanza would mean Splunk was only reading one local file?
Which forwarder is recommended by Splunk to use in a production environment?
When working with an indexer cluster, what changes with the global precedence when comparing to a standalone deployment?
There is a file with a vast amount of old data. Which of the following inputs.conf attributes would allow an admin to monitor the file for updates without indexing the pre-existing data?
After how many warnings within a rolling 30-day period will a license violation occur with an enforced
Enterprise license?
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?
Windows can prevent a Splunk forwarder from reading open files. If files need to be read while they are being written to, what type of input stanza needs to be created?
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
A log file contains 193 days worth of timestamped events. Which monitor stanza would be used to collect data 45 days old and newer from that log file?
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs
the following search over the last 24 hours:
index=*
What field can the administrator check to see the data distribution?
When enabling data integrity control, where does Splunk Enterprise store the hash files for each bucket?
A Universal Forwarder has the following active stanza in inputs . conf:
[monitor: //var/log]
disabled = O
host = 460352847
An event from this input has a timestamp of 10:55. What timezone will Splunk add to the event as part of indexing?
When configuring monitor inputs with whitelists or blacklists, what is the supported method of filtering the lists?
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
What options are available when creating custom roles? (select all that apply)
A Universal Forwarder is monitoring a very active syslog stream and as a result is unable to switch between destinations. How would an admin safely remediate this issue?
Which of the following statements describe deployment management? (select all that apply)
Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
Which option on the Add Data menu is most useful for testing data ingestion without creating inputs.conf?
How is data handled by Splunk during the input phase of the data ingestion process?
A security team needs to ingest a static file for a specific incident. The log file has not been collected previously and future updates to the file must not be indexed.
Which command would meet these needs?
Which artifact is required in the request header when creating an HTTP event?
In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?
Event example:
Assume a file is being monitored and the data was incorrectly indexed to an exclusive index. The index is
cleaned and now the data must be reindexed. What other index must be cleaned to reset the input checkpoint
information for that file?
Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?
Within props. conf, which stanzas are valid for data modification? (select all that apply)
In case of a conflict between a whitelist and a blacklist input setting, which one is used?
Load balancing on a Universal Forwarder is not scaling correctly. The forwarder's outputs. and the tcpout stanza are setup correctly. What else could be the cause of this scaling issue? (select all that apply)
When using license pools, volume allocations apply to which Splunk components?
Which of the following are methods for adding inputs in Splunk? (select all that apply)
Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as
follows: 123-44-5678.
Which configuration file and stanza pair will mask possible SSNs in the log events?
Which setting in indexes. conf allows data retention to be controlled by time?
The CLI command splunk add forward-server indexer:
which configuration file?
What is the default character encoding used by Splunk during the input phase?
A Splunk administrator has been tasked with developing a retention strategy to have frequently accessed data sets on SSD storage and to have older, less frequently accessed data on slower NAS storage. They have set a mount point for the NAS. Which parameter do they need to modify to set the path for the older, less frequently accessed data in indexes.conf?
An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data
is 300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the
index?
Which of the following is true when authenticating users to Splunk using LDAP?
Which Splunk configuration file is used to enable data integrity checking?