Big Halloween Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Splunk Splunk Enterprise Certified Admin SPLK-1003 Questions and answers with CertsForce

Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions
Questions # 31:

What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?

Options:

A.

Disk


B.

CPUs


C.

Memory


D.

Network interface cards


Expert Solution
Questions # 32:

What is a role in Splunk? (select all that apply)

Options:

A.

A classification that determines what capabilities a user has.


B.

A classification that determines if a Splunk server can remotely control another Splunk server.


C.

A classification that determines what functions a Splunk server controls.


D.

A classification that determines what indexes a user can search.


Expert Solution
Questions # 33:

Where are license files stored?

Options:

A.

$SPLUNK_HOME/etc/secure


B.

$SPLUNK_HOME/etc/system


C.

$SPLUNK_HOME/etc/licenses


D.

$SPLUNK_HOME/etc/apps/licenses


Expert Solution
Questions # 34:

The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require

multiple indexers. Following best practices, which types of Splunk component instances are needed?

Options:

A.

Indexers, search head, universal forwarders, license master


B.

Indexers, search head, deployment server, universal forwarders


C.

Indexers, search head, deployment server, license master, universal forwarder


D.

Indexers, search head, deployment server, license master, universal forwarder, heavy forwarder


Expert Solution
Questions # 35:

You update a props. conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btoo1 props list —debug. What will the output be?

Options:

A.

list of all the configurations on-disk that Splunk contains.


B.

A verbose list of all configurations as they were when splunkd started.


C.

A list of props. conf configurations as they are on-disk along with a file path from which the configuration is located


D.

A list of the current running props, conf configurations along with a file path from which the configuration was made


Expert Solution
Questions # 36:

What are the values forhostandindexfor[stanza1]used by Splunk during index time, given the following configuration files?

Question # 36

Options:

A.

host=server1index=unixinfo


B.

host=server1index=searchinfo


C.

host=searchsvr1index=searchinfo


D.

host=unixsvr1index=unixinfo


Expert Solution
Questions # 37:

The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs

the following search over the last 24 hours:

index=*

What field can the administrator check to see the data distribution?

Options:

A.

host


B.

index


C.

linecount


D.

splunk_server


Expert Solution
Questions # 38:

Which valid bucket types are searchable? (select all that apply)

Options:

A.

Hot buckets


B.

Cold buckets


C.

Warm buckets


D.

Frozen buckets


Expert Solution
Questions # 39:

Which of the following statements apply to directory inputs? {select all that apply)

Options:

A.

All discovered text files are consumed.


B.

Compressed files are ignored by default


C.

Splunk recursively traverses through the directory structure.


D.

When adding new log files to a monitored directory, the forwarder must be restarted to take them into account.


Expert Solution
Questions # 40:

Which option on the Add Data menu is most useful for testing data ingestion without creating inputs.conf?

Options:

A.

Upload option


B.

Forward option


C.

Monitor option


D.

Download option


Expert Solution
Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions