Pass the Splunk Splunk Enterprise Certified Admin SPLK-1003 Questions and answers with CertsForce

Viewing page 6 out of 6 pages
Viewing questions 51-60 out of questions
Questions # 51:

Which of the following statements apply to directory inputs? {select all that apply)

Options:

A.

All discovered text files are consumed.


B.

Compressed files are ignored by default


C.

Splunk recursively traverses through the directory structure.


D.

When adding new log files to a monitored directory, the forwarder must be restarted to take them into account.


Expert Solution
Questions # 52:

What event-processing pipelines are used to process data for indexing? (select all that apply)

Options:

A.

fifo pipeline


B.

Indexing pipeline


C.

Parsing pipeline


D.

Typing pipeline


Expert Solution
Questions # 53:

Assume a file is being monitored and the data was incorrectly indexed to an exclusive index. The index is

cleaned and now the data must be reindexed. What other index must be cleaned to reset the input checkpoint

information for that file?

Options:

A.

_audit


B.

_checkpoint


C.

_introspection


D.

_thefishbucket


Expert Solution
Questions # 54:

Which setting allows the configuration of Splunk to allow events to span over more than one line?

Options:

A.

SHOULD_LINEMERGE = true


B.

BREAK_ONLY_BEFORE_DATE = true


C.

BREAK_ONLY_BEFORE =


D.

SHOULD_LINEMERGE = false


Expert Solution
Questions # 55:

In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?

Options:

A.

services/collector


B.

data/collector


C.

services/inputs?raw


D.

services/data/collector


Expert Solution
Questions # 56:

All search-time field extractions should be specified on which Splunk component?

Options:

A.

Deployment server


B.

Universal forwarder


C.

Indexer


D.

Search head


Expert Solution
Questions # 57:

Which of the following CLI commands removes a search peer from Distributed Search?

Options:

A.

splunk remove search-server -auth admin:password 123.45.67.89:8089


B.

splunk clear search-server -auth admin:password 123.45.67.89:8089


C.

splunk clear search-peer -auth admin:password 123.45.67.89:8089


D.

splunk remove search-peer -auth admin:password 123.45.67.89:8089


Expert Solution
Questions # 58:

What is the default character encoding used by Splunk during the input phase?

Options:

A.

UTF-8


B.

UTF-16


C.

EBCDIC


D.

ISO 8859


Expert Solution
Viewing page 6 out of 6 pages
Viewing questions 51-60 out of questions