Pass the Splunk Splunk Cloud Certified Admin SPLK-1005 Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

In which of the following situations should Splunk Support be contacted?

Options:

A.

When a custom search needs tuning due to not performing as expected.


B.

When an app on Splunkbase indicates Request Install.


C.

Before using the delete command.


D.

When a new role that mirrors sc_admin is required.


Expert Solution
Questions # 12:

Which of the following is not considered a best practice for the deployment server?

Options:

A.

Create small, single-purpose deployment apps.


B.

Dedicate a Splunk instance as the deployment server.


C.

Use a Linux server as the deployment server.


D.

Create large, multi-purpose deployment apps.


Expert Solution
Questions # 13:

Given the following set of files, which of the monitor stanzas below will result in Splunk monitoring all of the files ending with .log?

Files:

    /var/log/www1/secure.log

    /var/log/www1/access.log

    /var/log/www2/logs/secure.log

    /var/log/www2/access.log

    /var/log/www2/access.log.1

Options:

A.

[monitor:///var/log/*/*.log]


B.

[monitor:///var/log/.../*.log]


C.

[monitor:///var/log/*/*]


D.

[monitor:///var/log/.../*]


Expert Solution
Questions # 14:

When monitoring network inputs, there will be times when the forwarder is unable to send data to the indexers. Splunk uses a memory queue and a disk queue. Which setting is used for the disk queue?

Options:

A.

queueSize


B.

maxQeueSize


C.

diskQiioiioiiizo


D.

persistentQueueSize


Expert Solution
Questions # 15:

Which of the following is the default bandwidth limit in the Splunk Universal Forwarder credentials package?

Options:

A.

0KBps


B.

256 KBps


C.

512 KBps


D.

1024 KBps


Expert Solution
Questions # 16:

Which of the following is true when integrating LDAP authentication?

Options:

A.

Splunk stores LDAP end user names and passwords on search heads.


B.

The mapping of LDAP groups to Splunk roles happens automatically.


C.

Splunk Cloud only supports Active Directory LDAP servers.


D.

New user data is cached the first time a user logs in.


Expert Solution
Questions # 17:

Which of the following are default Splunk Cloud user roles?

Options:

A.

must_delete, power, sc_admin


B.

power, user, admin


C.

apps, power, sc_admin


D.

can delete, users, admin


Expert Solution
Questions # 18:

Which of the following methods is valid for creating index-time field extractions?

Options:

A.

Use the UI to create a sourcetype, specify the field name and corresponding regular expression with capture statement.


B.

Create a configuration app with the index-time props.conf and/or transfoms. conf, and upload the app via UI.


C.

Use the CU app to define settings in fields.conf, and restart Splunk Cloud.


D.

Use the rex command to extract the desired field, and then save as a calculated field.


Expert Solution
Questions # 19:

For the following data, what would be the correct attribute/value oair to use to successfully extract the correct timestamp from all the events?

Question # 19

Options:

A.

TIMK_FORMAT = %b %d %H:%M:%S %z


B.

DATETIME CONFIG = %Y-%m-%d %H:%M:%S %2


C.

TIME_FORMAT = %b %d %H:%M:%S


D.

DATETIKE CONFIG = Sb %d %H:%M:%S


Expert Solution
Questions # 20:

In case of a Change Request, which of the following should submit a support case for Splunk Support?

Options:

A.

The party requesting the change.


B.

Certified Splunk Cloud administrator.


C.

Splunk infrastructure owner.


D.

Any person with the appropriate entitlement


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions