Big Halloween Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Splunk Splunk Enterprise Certified Admin SPLK-1003 Questions and answers with CertsForce

Viewing page 5 out of 6 pages
Viewing questions 41-50 out of questions
Questions # 41:

Seven different network switches are sending traffic to a server hosting a Universal Forwarder. Three of the devices are sending TCP data and four of the devices are sending UDP data.

What is the minimum number of input stanzas that must be created on the Universal Forwarder to successfully capture data from all seven sources?

Options:

A.

One


B.

Seven


C.

Four


D.

Two


Expert Solution
Questions # 42:

TheLINE_BREAKERattribute is configured in which configuration file?

Options:

A.

props.conf


B.

indexes.conf


C.

inpucs.conf


D.

transforms.conf


Expert Solution
Questions # 43:

In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?

Options:

A.

To ensure that hot buckets are still open for writes and have not been forced to roll to a cold state


B.

To ensure that configuration files have not been tampered with for auditing and/or legal purposes


C.

To ensure that user passwords have not been tampered with for auditing and/or legal purposes.


D.

To ensure that data has not been tampered with for auditing and/or legal purposes


Expert Solution
Questions # 44:

When would the following command be used?

Options:

A.

To verify' the integrity of a local index.


B.

To verify the integrity of a SmartStore index.


C.

To verify the integrity of a SmartStore bucket.


D.

To verify the integrity of a local bucket.


Expert Solution
Questions # 45:

Within props. conf, which stanzas are valid for data modification? (select all that apply)

Options:

A.

Host


B.

Server


C.

Source


D.

Sourcetype


Expert Solution
Questions # 46:

Which of the following is the use case for the deployment server feature of Splunk?

Options:

A.

Managing distributed workloads in a Splunk environment.


B.

Automating upgrades of Splunk forwarder installations on endpoints.


C.

Orchestrating the operations and scale of a containerized Splunk deployment.


D.

Updating configuration and distributing apps to processing components, primarily forwarders.


Expert Solution
Questions # 47:

What is the name of the object that stores events inside of an index?

Options:

A.

Container


B.

Bucket


C.

Data layer


D.

Indexer


Expert Solution
Questions # 48:

Which of the following must be done to define user permissions when integrating Splunk with LDAP?

Options:

A.

Map Users


B.

Map Groups


C.

Map LDAP Inheritance


D.

Map LDAP to Active Directory


Expert Solution
Questions # 49:

The following stanza is active in indexes.conf:

[cat_facts]

maxHotSpanSecs = 3600

frozenTimePeriodInSecs = 2630000

maxTota1DataSizeMB = 650000

All other related indexes.conf settings are default values.

If the event timestamp was 3739283 seconds ago, will it be searchable?

Options:

A.

Yes, only if the bucket is still hot.


B.

No, because the index will have exceeded its maximum size.


C.

Yes, only if the index size is also below 650000 MB.


D.

No, because the event time is greater than the retention time.


Expert Solution
Questions # 50:

Which of the following lists the three phases of the Splunk Indexing process in order?

Options:

A.

Ingest phaseLicensing phaseParsing phase


B.

Sourcetype phaseIndex phaseWrite-to-disk phase


C.

Input phaseParsing phaseIndexing phase


D.

Ingest phaseTransforming phaseIndexing phase


Expert Solution
Viewing page 5 out of 6 pages
Viewing questions 41-50 out of questions