The following stanza is active in indexes.conf:
[cat_facts]
maxHotSpanSecs = 3600
frozenTimePeriodInSecs = 2630000
maxTota1DataSizeMB = 650000
All other related indexes.conf settings are default values.
If the event timestamp was 3739283 seconds ago, will it be searchable?
You update a props. conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btoo1 props list —debug. What will the output be?
Which artifact is required in the request header when creating an HTTP event?
Which configuration file would be used to forward the Splunk internal logs from a search head to the indexer?
What is the default value ofLINE_BREAKER?
What is the default purpose of a Splunk Deployment Server?
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
What is the correct curl to send multiple events through HTTP Event Collector?
Immediately after installation, what will a Universal Forwarder do first?