Pass the Splunk Splunk Enterprise Certified Admin SPLK-1003 Questions and answers with CertsForce

Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions
Questions # 31:

Which of the following enables compression for universal forwarders in outputs. conf ?

A)

Question # 31

B)

Question # 31

C)

Question # 31

D)

Question # 31

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 32:

What will the following inputs. conf stanza do?

[script://myscript . sh]

Interval=0

Options:

A.

The script will run at the default interval of 60 seconds.


B.

The script will not be run.


C.

The script will be run only once for each time Splunk is restarted.


D.

The script will be run. As soon as the script exits, Splunk restarts it.


Expert Solution
Questions # 33:

What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?

Options:

A.

REGEX, DEST. FORMAT


B.

REGEX.SRC_KEY, FORMAT


C.

REGEX, DEST_KEY, FORMAT


D.

REGEX, DEST_KEY FORMATTING


Expert Solution
Questions # 34:

For single line event sourcetypes. it is most efficient to set SHOULD_linemerge to what value?

Options:

A.

True


B.

False


C.


D.

Newline Character


Expert Solution
Questions # 35:

Which Splunk component distributes apps and certain other configuration updates to search head cluster members?

Options:

A.

Deployer


B.

Cluster master


C.

Deployment server


D.

Search head cluster master


Expert Solution
Questions # 36:

In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?

Options:

A.

To ensure that hot buckets are still open for writes and have not been forced to roll to a cold state


B.

To ensure that configuration files have not been tampered with for auditing and/or legal purposes


C.

To ensure that user passwords have not been tampered with for auditing and/or legal purposes.


D.

To ensure that data has not been tampered with for auditing and/or legal purposes


Expert Solution
Questions # 37:

What configuration file are remote Windows Management Instrumentation inputs defined in?

Options:

A.

wmi_inputs.conf


B.

inputs.conf


C.

None, the inputs are defined outside of Splunk.


D.

wmi.conf


Expert Solution
Questions # 38:

Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?

Options:

A.

Any OS platform


B.

Linux platform only


C.

Windows platform only.


D.

None of the above.


Expert Solution
Questions # 39:

An admin oversees an environment with a 1000 GBI day license. The configuration file

server.conf has strict pool quota=false set. The license is divided into the following three pools, and today's usage is shown on the right-hand column:

PoolLicense SizeToday's usage

X500 GB/day100 GB

Y350 GB/day400 GB

Z150 GB/day300 GB

Given this, which pool(s) are issued warnings?

Options:

A.

All pools


B.

Z only


C.

None


D.

Y and Z


Expert Solution
Questions # 40:

What is the correct curl to send multiple events through HTTP Event Collector?

Question # 40

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions