Big Halloween Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-1003 Practice Exam with Questions & Answers | Set: 2

Questions 11

Which of the following must be done to define user permissions when integrating Splunk with LDAP?

Options:
A.

Map Users

B.

Map Groups

C.

Map LDAP Inheritance

D.

Map LDAP to Active Directory

Splunk SPLK-1003 Premium Access
Questions 12

After how many warnings within a rolling 30-day period will a license violation occur with an enforced

Enterprise license?

Options:
A.

1

B.

3

C.

4

D.

5

Questions 13

When working with an indexer cluster, what changes with the global precedence when comparing to a standalone deployment?

Options:
A.

Nothing changes.

B.

The peer-apps local directory becomes the highest priority.

C.

The app local directories move to second in the priority list.

D.

The system default directory' becomes the highest priority.

Questions 14

When deploying apps, which attribute in the forwarder management interface determines the apps that clients install?

Options:
A.

App Class

B.

Client Class

C.

Server Class

D.

Forwarder Class

Questions 15

When indexing a data source, which fields are considered metadata?

Options:
A.

source, host, time

B.

time, sourcetype, source

C.

host, raw, sourcetype

D.

sourcetype, source, host

Questions 16

Which file will be matched for the following monitor stanza in inputs. conf?

[monitor: ///var/log/*/bar/*. txt]

Options:
A.

/var/log/host_460352847/temp/bar/file/csv/foo.txt

B.

/var/log/host_460352847/bar/foo.txt

C.

/var/log/host_460352847/bar/file/foo.txt

D.

/var/ log/ host_460352847/temp/bar/file/foo.txt

Questions 17

Which of the following describes a Splunk deployment server?

Options:
A.

A Splunk Forwarder that deploys data to multiple indexers.

B.

A Splunk app installed on a Splunk Enterprise server.

C.

A Splunk Enterprise server that distributes apps.

D.

A server that automates the deployment of Splunk Enterprise to remote servers.

Questions 18

Which parent directory contains the configuration files in Splunk?

Options:
A.

SSFLUNK_HOME/etc

B.

SSPLUNK_HOME/var

C.

SSPLUNK_HOME/conf

D.

SSPLUNK_HOME/default

Questions 19

Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)

Options:
A.

props.conf

B.

inputs.conf

C.

rawdata.conf

D.

transforms.conf

Questions 20

A company moves to a distributed architecture to meet the growing demand for the use of Splunk. What parameter can be configured to enable automatic load balancing in the

Universal Forwarder to send data to the indexers?

Options:
A.

Create one outputs . conf file for each of the server addresses in the indexing tier.

B.

Configure the outputs . conf file to point to any server in the indexing tier and Splunk will configure the data to be sent to all of the indexers.

C.

Splunk does not do load balancing and requires a hardware load balancer to balance traffic across the indexers.

D.

Set the stanza to have a server value equal to a comma-separated list of IP addresses and indexer ports for each of the indexers in the environment.