Splunk SPLK-1003 - Splunk Enterprise Certified Admin
Which of the following statements describes how distributed search works?
In a distributed environment, which Splunk component is used to distribute apps and configurations to the
other Splunk instances?
Windows can prevent a Splunk forwarder from reading open files. If files need to be read while they are being written to, what type of input stanza needs to be created?
A Splunk administrator has been tasked with developing a retention strategy to have frequently accessed data sets on SSD storage and to have older, less frequently accessed data on slower NAS storage. They have set a mount point for the NAS. Which parameter do they need to modify to set the path for the older, less frequently accessed data in indexes.conf?
Which option on the Add Data menu is most useful for testing data ingestion without creating inputs.conf?
The following stanzas in inputs. conf are currently being used by a deployment client:
[udp: //145.175.118.177:1001
Connection_host = dns
sourcetype = syslog
Which of the following statements is true of data that is received via this input?
A log file contains 193 days worth of timestamped events. Which monitor stanza would be used to collect data 45 days old and newer from that log file?
Which Splunk component requires a Forwarder license?
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
How is data handled by Splunk during the input phase of the data ingestion process?