Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Splunk SPLK-1003 Practice Exam with Questions & Answers | Set: 3

Questions 21

In inputs. conf, which stanza would mean Splunk was only reading one local file?

Options:
A.

[read://opt/log/crashlog/Jan27crash.txt]

B.

[monitor::/ opt/log/crashlog/Jan27crash.txt]

C.

[monitor:/// opt/log/]

D.

[monitor:/// opt/log/ crashlog/Jan27crash.txt]

Splunk SPLK-1003 Premium Access
Questions 22

Which of the following is the recommended guideline for creating a new user role?

Options:
A.

Create a role that incorporates capabilities and index inheritance.

B.

Create a new unique role for each unique user.

C.

There are no recommended guidelines when creating new user roles.

D.

Create two roles based on capabilities and indexes, then utilize inheritance.

Questions 23

When using a directory monitor input, specific source type can be selectively overridden using which configuration file?

Options:
A.

props.conf

B.

sourcetypes.conf

C.

transforms.conf

D.

outputs.conf

Questions 24

What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?

Options:
A.

Disk

B.

CPUs

C.

Memory

D.

Network interface cards

Questions 25

What is a role in Splunk? (select all that apply)

Options:
A.

A classification that determines what capabilities a user has.

B.

A classification that determines if a Splunk server can remotely control another Splunk server.

C.

A classification that determines what functions a Splunk server controls.

D.

A classification that determines what indexes a user can search.

Questions 26

For single line event sourcetypes. it is most efficient to set SHOULD_linemerge to what value?

Options:
A.

True

B.

False

C.

D.

Newline Character

Questions 27

Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?

Options:
A.

splunk btool server list --debug

B.

splunk list forward-indexer

C.

splunk list forward-server

D.

splunk btool indexes list --debug

Questions 28

Running this search in a distributed environment:

On what Splunk component does the eval command get executed?

Options:
A.

Heavy Forwarders

B.

Universal Forwarders

C.

Search peers

D.

Search heads

Questions 29

Which of the following types of data count against the license daily quota?

Options:
A.

Replicated data

B.

splunkd logs

C.

Summary index data

D.

Windows internal logs

Questions 30

Which setting in indexes. conf allows data retention to be controlled by time?

Options:
A.

maxDaysToKeep

B.

moveToFrozenAfter

C.

maxDataRetentionTime

D.

frozenTimePeriodlnSecs