Big Halloween Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-1003 Practice Exam with Questions & Answers

Questions 1

What is the correct example to redact a plain-text password from raw events?

Options:
A.

in props.conf:[identity]REGEX-redact_pw = s/password=([^,|/s]+)/ ####REACTED####/g

B.

in props.conf:[identity]SEDCMD-redact_pw = s/password=([^,|/s]+)/ ####REACTED####/g

C.

in transforms.conf:[identity]SEDCMD-redact_pw = s/password=([^,|/s]+)/ ####REACTED####/g

D.

in transforms.conf:[identity]REGEX-redact_pw = s/password=([^,|/s]+)/ ####REACTED####/g

Splunk SPLK-1003 Premium Access
Questions 2

How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON

A)

SPLK-1003 Question 2

B)

SPLK-1003 Question 2

C)

SPLK-1003 Question 2

D)

SPLK-1003 Question 2

Options:
A.

option A

B.

Option B

C.

Option C

D.

Option D

Questions 3

Which Splunk component would one use to perform line breaking prior to indexing?

Options:
A.

Heavy Forwarder

B.

Universal Forwarder

C.

Search head

D.

This can only be done at the indexing layer.

Questions 4

What is the correct order of steps in Duo Multifactor Authentication?

Options:
A.

1 Request Login2. Connect to SAML server3 Duo MFA4 Create User session5 Authentication Granted 6. Log into Splunk

B.

1. Request Login 2 Duo MFA3. Authentication Granted 4 Connect to SAML server5. Log into Splunk6. Create User session

C.

1 Request Login2 Check authentication / group mapping3 Authentication Granted4. Duo MFA5. Create User session6. Log into Splunk

D.

1 Request Login 2 Duo MFA3. Check authentication / group mapping4 Create User session5. Authentication Granted6 Log into Splunk

Questions 5

Which Splunk component distributes apps and certain other configuration updates to search head cluster members?

Options:
A.

Deployer

B.

Cluster master

C.

Deployment server

D.

Search head cluster master

Questions 6

Where should apps be located on the deployment server that the clients pull from?

Options:
A.

$SFLUNK_KOME/etc/apps

B.

$SPLUNK_HCME/etc/sear:ch

C.

$SPLUNK_HCME/etc/master-apps

D.

$SPLUNK HCME/etc/deployment-apps

Questions 7

Which of the following statements apply to directory inputs? {select all that apply)

Options:
A.

All discovered text files are consumed.

B.

Compressed files are ignored by default

C.

Splunk recursively traverses through the directory structure.

D.

When adding new log files to a monitored directory, the forwarder must be restarted to take them into account.

Questions 8

In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?

Options:
A.

services/collector

B.

data/collector

C.

services/inputs?raw

D.

services/data/collector

Questions 9

How is data handled by Splunk during the input phase of the data ingestion process?

Options:
A.

Data is treated as streams.

B.

Data is broken up into events.

C.

Data is initially written to disk.

D.

Data is measured by the license meter.

Questions 10

A non-clustered Splunk environment has three indexers (A,B,C) and two search heads (X, Y). During a search executed on search head X, indexer A crashes. What is Splunk's response?

Options:
A.

Update the user in Splunk web informing them that the results of their search may be incomplete.

B.

Repeat the search request on indexer B without informing the user.

C.

Update the user in Splunk web that their results may be incomple and that Splunk will try to re-execute the search.

D.

Inform the user in Splunk web that their results may be incomplete and have them attempt the search from search head Y.