Loading questions...
Updated
Using SEDCMD in props.conf allows raw data to be modified. With the given event below, which option will mask the first three digits of the AcctID field resulting output: [22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Event:
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Which of the following accurately describes HTTP Event Collector indexer acknowledgement?
What action is required to enable forwarder management in Splunk Web?
Which of the following is accurate regarding the input phase?
When indexing a data source, which fields are considered metadata?
What is the default value of LINE_BREAKER?
Which of the following monitor inputs stanza headers would match all of the following files?
/var/log/www1/secure.log
/var/log/www/secure.l
/var/log/www/logs/secure.logs
/var/log/www2/secure.log
What are the values for host and index for [stanza1] used by Splunk during index time, given the following configuration files?
An index stores its data in buckets. Which default directories does Splunk use to store buckets? (Choose all that apply.)
The LINE_BREAKER attribute is configured in which configuration file?
This file has been manually created on a universal forwarder:
/opt/splunkforwarder/etc/apps/my_TA/local/inputs.conf
[monitor:///var/log/messages]
sourcetype=syslog
index=syslog
A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new inputs.conf file:
/opt/splunk/etc/deployment-apps/my_TA/local/inputs.conf
[monitor:///var/log/maillog]
sourcetype=maillog
index=syslog
Which file is now monitored?
After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?
A log file contains 193 days worth of timestamped events. Which monitor stanza would be used to collect data 45 days old and newer from that log file?
After an Enterprise Trial license expires, it will automatically convert to a Free license. How many days is an Enterprise Trial license valid before this conversion occurs?
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?
Which of the following is an appropriate description of a deployment server in a non-cluster environment?
Which Splunk forwarder has a built-in license?
What happens when the same username exists in Splunk as well as through LDAP?
Consider the following stanza in inputs.conf:
Which of the following applies only to Splunk index data integrity check?
Which of the following types of data count against the license daily quota?
In which phase of the index time process does the license metering occur?
Which default Splunk role could be assigned to provide users with the following capabilities?
Create saved searches -
Edit shared objects and alerts -
Not allowed to create custom roles
Which setting in indexes.conf allows data retention to be controlled by time?
Where should apps be located on the deployment server that the clients pull from?
What will the value of the source filed be for events generated by this scripts input?