Filters
Question type

Study Flashcards

With authentication methods are natively supported within Splunk Enterprise? (Choose all that apply.)


A) LDAP
B) SAML
C) RADIUS
D) Duo Multifactor Authentication

Correct Answer

verifed

verified

A,D

How would you configure your distsearch.conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_server_group=HOUSTON


A) [distributedSearch:NYC] default = false servers = nyc1:8089, nyc2:8089 [distributedSearch:HOUSTON] servers = houston1:8089, houston2:8089
B) [distributedSearch] servers =nyc1, nyc2, houston1, houston2 servers = nyc1, nyc2 servers = houston1, houston2
C) servers =nyc1:8089, nyc2:8089, houston1:8089, houston2:8089
D) servers =nyc1:8089; nyc2:8089; houston1:8089; houston2:8089 servers = nyc1:8089; nyc2:8089 servers = houston1:8089; houston2:8089

Correct Answer

verifed

verified

What are the minimum required settings when creating a network input in Splunk?


A) Protocol, port number
B) Protocol, port, location
C) Protocol, username, port
D) Protocol, IP, port number

Correct Answer

verifed

verified

A

Which setting in indexes.conf allows data retention to be controlled by time?


A) maxDaysToKeep
B) moveToFrozenAfter
C) maxDataRetentionTime
D) frozenTimePeriodInSecs

Correct Answer

verifed

verified

Where are license files stored?


A) $SPLUNK_HOME/etc/secure
B) $SPLUNK_HOME/etc/system
C) $SPLUNK_HOME/etc/licenses
D) $SPLUNK_HOME/etc/apps/licenses

Correct Answer

verifed

verified

The universal forwarder has which capabilities when sending data? (Select all that apply.)


A) Sending alerts
B) Compressing data
C) Obfuscating/hiding data
D) Indexer acknowledgement

Correct Answer

verifed

verified

Within props.conf , which stanzas are valid for data modification? (Choose all that apply.)


A) Host
B) Server
C) Source
D) Sourcetype

Correct Answer

verifed

verified

Which is a valid stanza for a network input?


A) [udp://172.16.10.1:9997] connection = dns sourcetype = dns
B) [any://172.16.10.1:10001] connection_host = ip sourcetype = web
C) [tcp://172.16.10.1:9997] connection_host = web
D) [tcp://172.16.10.1:10001] connection_host = dns

Correct Answer

verifed

verified

What is required when adding a native user to Splunk? (Choose all that apply.)


A) Password
B) Username
C) Full Name
D) Default app

Correct Answer

verifed

verified

Which option accurately describes the purpose of the HTTP Event Collector (HEC) ?


A) A token-based HTTP input that is secure and scalable and that requires the use of forwarders.
B) A token-based HTTP input that is secure and scalable and that does not require the use of forwarders.
C) An agent-based HTTP input that is secure and scalable and that does not require the use of forwarders.
D) A token-based HTTP input that is insecure and non-scalable and that does not require the use of forwarders.

Correct Answer

verifed

verified

The universal forwarder has which capabilities when sending data? (Choose all that apply.)


A) Sending alerts
B) Compressing data
C) Obfuscating/hiding data
D) Indexer acknowledgement

Correct Answer

verifed

verified

How can native authentication be disabled in Splunk?


A) Remove the $SPLUNK_HOME/etc/passwd file Remove the $SPLUNK_HOME/etc/passwd file
B) Create an empty $SPLUNK_HOME/etc/passwd file Create an empty
C) Set SPLUNK_AUTHENTICATION=false in splunk-launch.conf Set SPLUNK_AUTHENTICATION=false in splunk-launch.conf
D) Set nativeAuthentication=false in authentication.conf nativeAuthentication=false authentication.conf

Correct Answer

verifed

verified

The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs the following search over the last 24 hours: index=* What field can the administrator check to see the data distribution?


A) host
B) index
C) linecount
D) splunk_server

Correct Answer

verifed

verified

D

On the deployment server, administrators can map clients to server classes using client filters. Which of the following statements is accurate?


A) The blacklist takes precedence over the whitelist.
B) The whitelist takes precedence over the blacklist.
C) Wildcards are not supported in any client filters.
D) Machine type filters are applied before the whitelist and blacklist.

Correct Answer

verifed

verified

Which of the following are methods for adding inputs in Splunk? (Select all that apply.)


A) CLI
B) Splunk Web
C) Editing inpits.conf Editing inpits.conf
D) Editing monitor.conf monitor.conf

Correct Answer

verifed

verified

The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require multiple indexers. Following best practices, which types of Splunk component instances are needed?


A) Indexers, search head, universal forwarders, license master
B) Indexers, search head, deployment server, universal forwarders
C) Indexers, search head, deployment server, license master, universal forwarder
D) Indexers, search head, deployment server, license master, universal forwarder, heavy forwarder

Correct Answer

verifed

verified

Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)


A) props.conf
B) inputs.conf
C) rawdata.conf
D) transforms.conf

Correct Answer

verifed

verified

Which of the following statements describe deployment management? (Select all that apply.)


A) Requires an Enterprise license.
B) Is responsible for sending apps to forwarders.
C) Once used, is the only way to manage forwarders.
D) Can automatically restart the host OS running the forwarder.

Correct Answer

verifed

verified

Which of the following configuration files are used with a universal forwarder? (Choose all that apply.)


A) inputs.conf
B) monitor.conf
C) outputs.conf
D) forwarder.conf

Correct Answer

verifed

verified

This file has been manually created on a universal forwarder: /opt/splunkforwarder/etc/apps/my_TA/local/inputs.conf [monitor:///var/log/messages] sourcetype=syslog index=syslog A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new inputs.conf file: /opt/splunk/etc/deployment-apps/my_TA/local/inputs.conf [monitor:///var/log/maillog] sourcetype=maillog Which file is now monitored?


A) /var/log/messages
B) /var/log/maillog
C) /var/log/maillog and /var/log/messages and
D) none of the above

Correct Answer

verifed

verified

Showing 1 - 20 of 84

Related Exams

Show Answer