Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Splunk Splunk Enterprise Certified Admin SPLK-1003 Questions and answers with CertsForce

Viewing page 6 out of 7 pages
Viewing questions 51-60 out of questions
Questions # 51:

In inputs. conf, which stanza would mean Splunk was only reading one local file?

Options:

A.

[read://opt/log/crashlog/Jan27crash.txt]


B.

[monitor::/ opt/log/crashlog/Jan27crash.txt]


C.

[monitor:/// opt/log/]


D.

[monitor:/// opt/log/ crashlog/Jan27crash.txt]


Expert Solution
Questions # 52:

A company moves to a distributed architecture to meet the growing demand for the use of Splunk. What parameter can be configured to enable automatic load balancing in the

Universal Forwarder to send data to the indexers?

Options:

A.

Create one outputs . conf file for each of the server addresses in the indexing tier.


B.

Configure the outputs . conf file to point to any server in the indexing tier and Splunk will configure the data to be sent to all of the indexers.


C.

Splunk does not do load balancing and requires a hardware load balancer to balance traffic across the indexers.


D.

Set the stanza to have a server value equal to a comma-separated list of IP addresses and indexer ports for each of the indexers in the environment.


Expert Solution
Questions # 53:

A security team needs to ingest a static file for a specific incident. The log file has not been collected previously and future updates to the file must not be indexed.

Which command would meet these needs?

Options:

A.

splunk add one shot / opt/ incident [data .log —index incident


B.

splunk edit monitor /opt/incident/data.* —index incident


C.

splunk add monitor /opt/incident/data.log —index incident


D.

splunk edit oneshot [opt/ incident/data.* —index incident


Expert Solution
Questions # 54:

The CLI command splunk add forward-server indexer: < receiving-port > will create stanza(s) in

which configuration file?

Options:

A.

inputs.conf


B.

indexes.conf


C.

outputs.conf


D.

servers.conf


Expert Solution
Questions # 55:

Which of the following is a valid method to create a Splunk user?

Options:

A.

Create a support ticket.


B.

Create a user on the host operating system.


C.

Splunk REST API.


D.

Add the username to users. conf.


Expert Solution
Questions # 56:

Which of the following indexes come pre-configured with Splunk Enterprise? (select all that apply)

Options:

A.

_license


B.

_lnternal


C.

_external


D.

_thefishbucket


Expert Solution
Questions # 57:

An admin oversees an environment with a 1000 GBI day license. The configuration file

server.conf has strict pool quota=false set. The license is divided into the following three pools, and today ' s usage is shown on the right-hand column:

PoolLicense SizeToday ' s usage

X500 GB/day100 GB

Y350 GB/day400 GB

Z150 GB/day300 GB

Given this, which pool(s) are issued warnings?

Options:

A.

All pools


B.

Z only


C.

None


D.

Y and Z


Expert Solution
Questions # 58:

In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?

Event example:

Options:

A.

MAX_TIMESTAMP_L0CKAHEAD = 5


B.

MAX_TIMESTAMP_LOOKAHEAD - 10


C.

MAX_TIMESTAMF_LOOKHEAD = 20


D.

MAX TIMESTAMP LOOKAHEAD - 30


Expert Solution
Questions # 59:

What is the default character encoding used by Splunk during the input phase?

Options:

A.

UTF-8


B.

UTF-16


C.

EBCDIC


D.

ISO 8859


Expert Solution
Questions # 60:

An organization wants to collect Windows performance data from a set of clients, however, installing Splunk

software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?

Options:

A.

Use Local Windows host monitoring.


B.

Use Windows Remote Inputs with WMI.


C.

Use Local Windows network monitoring.


D.

Use an index with an Index Data Type of Metrics.


Expert Solution
Viewing page 6 out of 7 pages
Viewing questions 51-60 out of questions