Pass the Splunk Splunk Enterprise Certified Admin SPLK-1003 Questions and answers with CertsForce

Viewing page 2 out of 6 pages
Viewing questions 11-20 out of questions
Questions # 11:

Where can scripts for scripted inputs reside on the host file system? (select all that apply)

Options:

A.

$SFLUNK_HOME/bin/scripts


B.

$SPLUNK_HOME/etc/apps/bin


C.

$SPLUNK_HOME/etc/system/bin


D.

$S?LUNK_HOME/etc/apps//bin_


Expert Solution
Questions # 12:

Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?

Options:

A.

diskQueueSize


B.

durableQueueSizeC persistentOueueSize


C.

queueSize


Expert Solution
Questions # 13:

Load balancing on a Universal Forwarder is not scaling correctly. The forwarder's outputs. and the tcpout stanza are setup correctly. What else could be the cause of this scaling issue? (select all that apply)

Options:

A.

The receiving port is not properly setup to listen on the right port.


B.

The inputs . conf'S _SYSZOG_ROVTING is not setup to use the right group names.


C.

The DNS record used is not setup with a valid list of IP addresses.


D.

The indexAndForward value is not set properly.


Expert Solution
Questions # 14:

Which of the following configuration files are used with a universal forwarder? (Choose all that apply.)

Options:

A.

inputs.conf


B.

monitor.conf


C.

outputs.conf


D.

forwarder.conf


Expert Solution
Questions # 15:

Immediately after installation, what will a Universal Forwarder do first?

Options:

A.

Automatically detect any indexers in its subnet and begin routing data.


B.

Begin generating internal Splunk logs.


C.

Begin reading local files on its server.


D.

Send an email to the operator that the installation process has completed.


Expert Solution
Questions # 16:

After how many warnings within a rolling 30-day period will a license violation occur with an enforced

Enterprise license?

Options:

A.

1


B.

3


C.

4


D.

5


Expert Solution
Questions # 17:

Which of the following are reasons to create separate indexes? (Choose all that apply.)

Options:

A.

Different retention times.


B.

Increase number of users.


C.

Restrict user permissions.


D.

File organization.


Expert Solution
Questions # 18:

When running the command shown below, what is the default path in which deployment server. conf is created?

splunk set deploy-poll deployServer:port

Options:

A.

SFLUNK_HOME/etc/deployment


B.

SPLUNK_HOME/etc/system/local


C.

SPLUNK_HOME/etc/system/default


D.

SPLUNK_KOME/etc/apps/deployment


Expert Solution
Questions # 19:

You update a props. conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btoo1 props list —debug. What will the output be?

Options:

A.

list of all the configurations on-disk that Splunk contains.


B.

A verbose list of all configurations as they were when splunkd started.


C.

A list of props. conf configurations as they are on-disk along with a file path from which the configuration is located


D.

A list of the current running props, conf configurations along with a file path from which the configuration was made


Expert Solution
Questions # 20:

When configuring monitor inputs with whitelists or blacklists, what is the supported method of filtering the lists?

Options:

A.

Slash notation


B.

Regular expression


C.

Irregular expression


D.

Wildcard-only expression


Expert Solution
Viewing page 2 out of 6 pages
Viewing questions 11-20 out of questions