Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Splunk SPLK-1005 Practice Exam with Questions & Answers | Set: 3

Questions 21

Given the following set of files, which of the monitor stanzas below will result in Splunk monitoring all of the files ending with .log?

Files:

    /var/log/www1/secure.log

    /var/log/www1/access.log

    /var/log/www2/logs/secure.log

    /var/log/www2/access.log

    /var/log/www2/access.log.1

Options:
A.

[monitor:///var/log/*/*.log]

B.

[monitor:///var/log/.../*.log]

C.

[monitor:///var/log/*/*]

D.

[monitor:///var/log/.../*]

Splunk SPLK-1005 Premium Access
Questions 22

Which configuration shown is used to enable a forwarder as a deployment client of the server 10.1.2.3?

Options:
A.

[target-broker:deploymentServer] targetUri = 10.1.2.3:9997

B.

[target-broker:deploymentserver] targetUri = 10.1.2.3:8089

C.

[target-broker:deploymentserver] deploymentserver = 10.1.2.3:9997

D.

[target-broker:deploymentserver] deploymentserver = 10.1.2.3:8089

Questions 23

What two files are used in the data transformation process?

Options:
A.

parsing.conf and transforms.conf

B.

props.conf and transforms.conf

C.

transforms.conf and fields.conf

D.

transforms.conf and sourcetypes.conf

Questions 24

What syntax is required in inputs.conf to ingest data from files or directories?

Options:
A.

A monitor stanza, sourcetype, and Index is required to ingest data.

B.

A monitor stanza, sourcetype, index, and host is required to ingest data.

C.

A monitor stanza and sourcetype is required to ingest data.

D.

Only the monitor stanza is required to ingest data.