Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-1003 Practice Exam with Questions & Answers | Set: 5

Questions 41

When Splunk is integrated with LDAP, which attribute can be changed in the Splunk UI for an LDAP user?

Options:
A.

Default app

B.

LDAP group

C.

Password

D.

Username

Splunk SPLK-1003 Premium Access
Questions 42

Immediately after installation, what will a Universal Forwarder do first?

Options:
A.

Automatically detect any indexers in its subnet and begin routing data.

B.

Begin generating internal Splunk logs.

C.

Begin reading local files on its server.

D.

Send an email to the operator that the installation process has completed.

Questions 43

Which of the following indexes come pre-configured with Splunk Enterprise? (select all that apply)

Options:
A.

_license

B.

_lnternal

C.

_external

D.

_thefishbucket

Questions 44

The priority of layered Splunk configuration files depends on the file's:

Options:
A.

Owner

B.

Weight

C.

Context

D.

Creation time

Questions 45

Which Splunk component would one use to perform line breaking prior to indexing?

Options:
A.

Heavy Forwarder

B.

Universal Forwarder

C.

Search head

D.

This can only be done at the indexing layer.

Questions 46

A Splunk administrator has been tasked with developing a retention strategy to have frequently accessed data sets on SSD storage and to have older, less frequently accessed data on slower NAS storage. They have set a mount point for the NAS. Which parameter do they need to modify to set the path for the older, less frequently accessed data in indexes.conf?

Options:
A.

homepath

B.

thawedPath

C.

summaryHomePath

D.

colddeath

Questions 47

What options are available when creating custom roles? (select all that apply)

Options:
A.

Restrict search terms

B.

Whitelist search terms

C.

Limit the number of concurrent search jobs

D.

Allow or restrict indexes that can be searched.

Questions 48

How often does Splunk recheck the LDAP server?

Options:
A.

Every 5 minutes

B.

Each time a user logs in

C.

Each time Splunk is restarted

D.

Varies based on LDAP_refresh setting.

Questions 49

What configuration file are remote Windows Management Instrumentation inputs defined in?

Options:
A.

wmi_inputs.conf

B.

inputs.conf

C.

None, the inputs are defined outside of Splunk.

D.

wmi.conf

Questions 50

There is a file with a vast amount of old data. Which of the following inputs.conf attributes would allow an admin to monitor the file for updates without indexing the pre-existing data?

Options:
A.

IgnoreOlderThan

B.

allowList

C.

monitor

D.

followTail