Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Splunk SPLK-1005 Practice Exam with Questions & Answers | Set: 2

Questions 11

For the following data, what would be the correct attribute/value oair to use to successfully extract the correct timestamp from all the events?

SPLK-1005 Question 11

Options:
A.

TIMK_FORMAT = %b %d %H:%M:%S %z

B.

DATETIME CONFIG = %Y-%m-%d %H:%M:%S %2

C.

TIME_FORMAT = %b %d %H:%M:%S

D.

DATETIKE CONFIG = Sb %d %H:%M:%S

Splunk SPLK-1005 Premium Access
Questions 12

What is the correct syntax to monitor /apache/too/logo, /apache/bor/logs, and /apache/bar/l/logo?

A)

SPLK-1005 Question 12

B)

SPLK-1005 Question 12

C)

SPLK-1005 Question 12

D)

SPLK-1005 Question 12

Options:
A.

Option A

B.

Option B

C.

Option C

D.

Option D

Questions 13

Which of the following is correct in regard to configuring a Universal Forwarder as an Intermediate Forwarder?

Options:
A.

This can only be turned on using the Settings > Forwarding and Receiving menu in Splunk Web/UI.

B.

The configuration changes can be made using Splunk Web. CU, directly in configuration files, or via a deployment app.

C.

The configuration changes can be made using CU, directly in configuration files, or via a deployment app.

D.

It is only possible to make this change directly in configuration files or via a deployment app.

Questions 14

A customer wants to mask unstructured data before sending it to Splunk Cloud. Where should SEBCMD be configured for this?

Options:
A.

props. conf on a Splunk Cloud search head,

B.

props.conf on a Heavy Forwarder.

C.

transforms, cent on a Splunk Cloud indexer.

D.

props. conf- on a Universal Forwarder.

Questions 15

Which of the following is true when integrating LDAP authentication?

Options:
A.

Splunk stores LDAP end user names and passwords on search heads.

B.

The mapping of LDAP groups to Splunk roles happens automatically.

C.

Splunk Cloud only supports Active Directory LDAP servers.

D.

New user data is cached the first time a user logs in.

Questions 16

A monitor has been created in inputs. con: for a directory that contains a mix of file types.

How would a Cloud Admin fine-tune assigned sourcetypes for different files in the directory during the input phase?

Options:
A.

On the Indexer parsing the data, leave sourcetype as automatic for the directory monitor. Then create a props.conf that assigns a specific sourcetype by source stanza.

B.

On the forwarder collecting the data, leave sourcetype as automatic for the directory monitor. Then create a props. conf that assigns a specific sourcetype by source stanza.

C.

On the Indexer parsing the data, set multiple sourcetype_source attributes for the directory monitor collecting the files. Then create a props, com that filters out unwanted files.

D.

On the forwarder collecting the data, set multiple 3ourcotype_sourc« attributes for the directory monitor collecting the files. Then create a props. conf that filters out unwanted files.

Questions 17

At what point in the indexing pipeline set is SEDCMD applied to data?

SPLK-1005 Question 17

Options:
A.

In the aggregator queue

B.

In the parsing queue

C.

In the exec pipeline

D.

In the typing pipeline

Questions 18

What does the followTail attribute do in inputs.conf?

Options:
A.

Pauses a file monitor if the queue is full.

B.

Only creates a tail checkpoint of the monitored file.

C.

Ingests a file starting with new content and then reading older events.

D.

Prevents pre-existing content in a file from being ingested.

Questions 19

In which file can the SH0ULD_LINEMERCE setting be modified?

Options:
A.

transforms.conf

B.

inputs.conf

C.

props.conf

D.

outputs.conf

Questions 20

Consider the following configurations:

SPLK-1005 Question 20

What is the value of the sourcetype property for this stanza based on Splunk's configuration file precedence?

Options:
A.

NULL, or unset, due to configuration conflict

B.

access_corabined

C.

linux aacurs

D.

linux_secure, access_combined