Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Splunk Splunk Enterprise Certified Admin SPLK-1003 Questions and answers with CertsForce

Viewing page 2 out of 7 pages
Viewing questions 11-20 out of questions
Questions # 11:

When enabling data integrity control, where does Splunk Enterprise store the hash files for each bucket?

Options:

A.

Splunk Enterprise stores hash files in the logdata directory of the corresponding bucket.


B.

Splunk Enterprise stores hash files in the rawdata directory of the corresponding bucket.


C.

Splunk Enterprise stores hash files in the hashdata directory of the corresponding bucket.


D.

Splunk Enterprise stores hash files in the metadata directory of the corresponding bucket.


Expert Solution
Questions # 12:

Assume a file is being monitored and the data was incorrectly indexed to an exclusive index. The index is

cleaned and now the data must be reindexed. What other index must be cleaned to reset the input checkpoint

information for that file?

Options:

A.

_audit


B.

_checkpoint


C.

_introspection


D.

_thefishbucket


Expert Solution
Questions # 13:

Where are license files stored?

Options:

A.

$SPLUNK_HOME/etc/secure


B.

$SPLUNK_HOME/etc/system


C.

$SPLUNK_HOME/etc/licenses


D.

$SPLUNK_HOME/etc/apps/licenses


Expert Solution
Questions # 14:

Which of the following are available input methods when adding a file input in Splunk Web? (Choose all that

apply.)

Options:

A.

Index once.


B.

Monitor interval.


C.

On-demand monitor.


D.

Continuously monitor.


Expert Solution
Questions # 15:

Which of the following statements describe deployment management? (select all that apply)

Options:

A.

Requires an Enterprise license


B.

Is responsible for sending apps to forwarders.


C.

Once used, is the only way to manage forwarders


D.

Can automatically restart the host OS running the forwarder.


Expert Solution
Questions # 16:

What are the values forhostandindexfor[stanza1]used by Splunk during index time, given the following configuration files?

Options:

A.

host=server1index=unixinfo


B.

host=server1index=searchinfo


C.

host=searchsvr1index=searchinfo


D.

host=unixsvr1index=unixinfo


Expert Solution
Questions # 17:

Which forwarder is recommended by Splunk to use in a production environment?

Options:

A.

Heavy forwarder


B.

SSL forwarder


C.

Lightweight forwarder


D.

Universal forwarder


Expert Solution
Questions # 18:

Event processing occurs at which phase of the data pipeline?

Options:

A.

Search


B.

Indexing


C.

Parsing


D.

Input


Expert Solution
Questions # 19:

What is an example of a proper configuration for CHARSET within props.conf?

Options:

A.

[host: : server. splunk. com]CHARSET = BIG5


B.

[index: :main]CHARSET = BIG5


C.

[sourcetype: : son]CHARSET = BIG5


D.

[source: : /var/log/ splunk]CHARSET = BIG5


Expert Solution
Questions # 20:

Which of the following is true regarding LDAP integration with Splunk Enterprise?

Options:

A.

Having the change authentication capability will not allow setup of the LDAP integration.


B.

Mappings can be changed at any time if the user has the power role.


C.

A user cannot log in via LDAP unless they have an associated Splunk role.


D.

LDAP integration will not function unless all groups are mapped to an LDAP group.


Expert Solution
Viewing page 2 out of 7 pages
Viewing questions 11-20 out of questions