Big Halloween Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Splunk Splunk Enterprise Certified Admin SPLK-1003 Questions and answers with CertsForce

Viewing page 2 out of 6 pages
Viewing questions 11-20 out of questions
Questions # 11:

What is the command to reset the fishbucket for one source?

Options:

A.

rm -r ~/splunkforwarder/var/lib/splunk/fishbucket


B.

splunk clean eventdata -index _thefishbucket


C.

splunk cmd btprobe -d SPLUNK_HOME/var/lib/splunk/fishbucket/splunk_private_db --file --reset


D.

splunk btool fishbucket reset


Expert Solution
Questions # 12:

Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?

Options:

A.

Indexer


B.

Deployment server


C.

Universal forwarder


D.

Search head


Expert Solution
Questions # 13:

Which of the following is valid distribute search group?

A)

B)

Question # 13

C)

Question # 13

D)

Options:

A.

option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 14:

A Universal Forwarder is collecting two separate sources of data (A,B). Source A is being routed through a Heavy Forwarder and then to an indexer. Source B is being routed directly to the indexer. Both sets of data require the masking of raw text strings before being written to disk. What does the administrator need to do to

ensure that the masking takes place successfully?

Options:

A.

Make sure that props . conf and transforms . conf are both present on the in-dexer and the search head.


B.

For source A, make sure that props . conf is in place on the indexer; and for source B, make sure transforms . conf is present on the Heavy Forwarder.


C.

Make sure that props . conf and transforms . conf are both present on the Universal Forwarder.


D.

Place both props . conf and transforms . conf on the Heavy Forwarder for source A, and place both props . conf and transforms . conf on the indexer for source B.


Expert Solution
Questions # 15:

An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data

is 300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the

index?

Options:

A.

Buy a bigger Splunk license.


B.

Add 2.5 TB each day for the next 5 days.


C.

Add all 10 TB in a single 24 hour period.


D.

Add 200 GB of historical data each day for 50 days.


Expert Solution
Questions # 16:

Which Splunk component does a search head primarily communicate with?

Options:

A.

Indexer


B.

Forwarder


C.

Cluster master


D.

Deployment server


Expert Solution
Questions # 17:

Which of the following is a benefit of distributed search?

Options:

A.

Peers run search in sequence.


B.

Peers run search in parallel.


C.

Resilience from indexer failure.


D.

Resilience from search head failure.


Expert Solution
Questions # 18:

How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON

A)

Question # 18

B)

Question # 18

C)

Question # 18

D)

Question # 18

Options:

A.

option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 19:

Which of the following monitor inputs stanza headers would match all of the following files?

/var/log/www1/secure.log

/var/log/www/secure.l

/var/log/www/logs/secure.logs

/var/log/www2/secure.log

Options:

A.

[monitor:///var/log/.../secure.*


B.

[monitor:///var/log/www1/secure.*]


C.

[monitor:///var/log/www1/secure.log]


D.

[monitor:///var/log/www*/secure.*]


Expert Solution
Questions # 20:

Which of the following enables compression for universal forwarders in outputs. conf ?

A)

Question # 20

B)

Question # 20

C)

Question # 20

D)

Question # 20

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Viewing page 2 out of 6 pages
Viewing questions 11-20 out of questions