Splunk Enterprise Certified Architect SPLK-2002 Question # 7 Topic 1 Discussion

Splunk Enterprise Certified Architect SPLK-2002 Question # 7 Topic 1 Discussion

SPLK-2002 Exam Topic 1 Question 7 Discussion:
Question #: 7
Topic #: 1

A monitored log file is changing on the forwarder. However, Splunk searches are not finding any new data that has been added. What are possible causes? (select all that apply)


A.

An admin ran splunk clean eventdata -index on the indexer.


B.

An admin has removed the Splunk fishbucket on the forwarder.


C.

The last 256 bytes of the monitored file are not changing.


D.

The first 256 bytes of the monitored file are not changing.


Get Premium SPLK-2002 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.