Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-1005 Practice Exam with Questions & Answers

Questions 1

When monitoring network inputs, there will be times when the forwarder is unable to send data to the indexers. Splunk uses a memory queue and a disk queue. Which setting is used for the disk queue?

Options:
A.

queueSize

B.

maxQeueSize

C.

diskQiioiioiiizo

D.

persistentQueueSize

Splunk SPLK-1005 Premium Access
Questions 2

Which of the following is not a path used by Splunk to execute scripts?

Options:
A.

SPLUNK_HOME/etc/system/bin

B.

SPLUNK HOME/etc/appa/<app name>/bin

C.

SPLUNKHOMS/ctc/scripts/local

D.

SPLUNK_HOME/bin/scripts

Questions 3

What is the name of the Splunk index that contains the most valuable information for troubleshooting a Splunk issue?

Options:
A.

_internal

B.

lastchanceindex

C.

_monitoring

D.

defaultdb

Questions 4

Which of the following is a valid stanza in props. conf?

Options:
A.

[sourcetype::linux_secure]

B.

[host=nyc25]

C.

[host::nyc*]

D.

[host:nyc*]

Questions 5

The following Apache access log is being ingested into Splunk via a monitor input:

SPLK-1005 Question 5

How does Splunk determine the time zone for this event?

Options:
A.

The value of the TZ attribute in props. cont for the a :ces3_ccwbined sourcetype.

B.

The value of the TZ attribute in props, conf for the my.webserver.example host.

C.

The time zone of the Heavy/Intermediate Forwarder with the monitor input.

D.

The time zone indicator in the raw event data.

Questions 6

Files from multiple systems are being stored on a centralized log server. The files are organized into directories based on the original server they came from. Which of the following is a recommended approach for correctly setting the host values based on their origin?

Options:
A.

Use the host segment, setting.

B.

Set host = * in the monitor stanza.

C.

The host value cannot be dynamically set.

D.

Manually create a separate monitor stanza for each host, with the nose = value set.

Questions 7

Which of the following are default Splunk Cloud user roles?

Options:
A.

must_delete, power, sc_admin

B.

power, user, admin

C.

apps, power, sc_admin

D.

can delete, users, admin

Questions 8

Which of the following tasks is not managed by the Splunk Cloud administrator?

Options:
A.

Forwarding events to Splunk Cloud.

B.

Upgrading the indexer's Splunk software.

C.

Managing knowledge objects.

D.

Creating users and roles.

Questions 9

What Splunk command will allow an administrator to view the runtime configuration instructions for a monitored file in Inputs. cont on the forwarders?

Options:
A.

./splunk _internal call /services/data/input.3/filemonitor

B.

./splunk show config inputs.conf

C.

./splunk _internal rest /services/data/inputs/monitor

D.

./splunk show config inputs

Questions 10

Which of the following statements regarding apps in Splunk Cloud is true?

Options:
A.

Self-service install of premium apps is possible.

B.

Only Cloud certified and vetted apps are supported.

C.

Any app that can be deployed in an on-prem Splunk Enterprise environment is also supported on Splunk Cloud.

D.

Self-service install is available for all apps on Splunkbase.