Big Halloween Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-1003 Practice Exam with Questions & Answers | Set: 6

Questions 51

There is a file with a vast amount of old data. Which of the following inputs.conf attributes would allow an admin to monitor the file for updates without indexing the pre-existing data?

Options:
A.

IgnoreOlderThan

B.

allowList

C.

monitor

D.

followTail

Splunk SPLK-1003 Premium Access
Questions 52

Which Splunk component(s) would break a stream of syslog inputs into individual events? (select all that apply)

Options:
A.

Universal Forwarder

B.

Search head

C.

Heavy Forwarder

D.

Indexer

Questions 53

Which option accurately describes the purpose of the HTTP Event Collector (HEC)?

Options:
A.

A token-based HTTP input that is secure and scalable and that requires the use of forwarders

B.

A token-based HTTP input that is secure and scalable and that does not require the use of forwarders.

C.

An agent-based HTTP input that is secure and scalable and that does not require the use of forwarders.

D.

A token-based HTTP input that is insecure and non-scalable and that does not require the use of forwarders.

Questions 54

A request has been made to restrict lookup files up to 500 megabytes for replication. Anything larger should not be replicated. Which of the following parameters provides the correct control for this scenario?

Options:
A.

maxBundleSize

B.

maxMemoryBundleSize

C.

excludeReplicatedLookupSize

D.

includeReplicatedLookupSize

Questions 55

Where are license files stored?

Options:
A.

$SPLUNK_HOME/etc/secure

B.

$SPLUNK_HOME/etc/system

C.

$SPLUNK_HOME/etc/licenses

D.

$SPLUNK_HOME/etc/apps/licenses

Questions 56

Syslog files are being monitored on a Heavy Forwarder.

Where would the appropriate TRANSFORMS setting be deployed to reroute logs based on the event message?

Options:
A.

Heavy Forwarder

B.

Indexer

C.

Search head

D.

Deployment server

Questions 57

What is the default value ofLINE_BREAKER?

Options:
A.

\r\n

B.

([\r\n]+)

C.

\r+\n+

D.

(\r\n+)

Questions 58

Which of the following methods will connect a deployment client to a deployment server? (select all that apply)

Options:
A.

Run $SPLUNK_ROME/bin/ splunk set deploy-poll : from the command line of the deployment client.

B.

Create and edit a deploymentserver . conf file in SSPLVNE{ on the deployment server.

C.

Create and edit a deploymentclient . conf file in SSPLTJNE( EOME/etc/ system/local on the deployment client.

D.

Run $SPLUNK ROME/bin/spiunk set deploy-poi i : from the command line of the deployment server.

Questions 59

The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require

multiple indexers. Following best practices, which types of Splunk component instances are needed?

Options:
A.

Indexers, search head, universal forwarders, license master

B.

Indexers, search head, deployment server, universal forwarders

C.

Indexers, search head, deployment server, license master, universal forwarder

D.

Indexers, search head, deployment server, license master, universal forwarder, heavy forwarder

Questions 60

Which of the following is a valid method to create a Splunk user?

Options:
A.

Create a support ticket.

B.

Create a user on the host operating system.

C.

Splunk REST API.

D.

Add the username to users. conf.