Splunk SPLK-1003 - Splunk Enterprise Certified Admin
Which optional configuration setting in inputs .conf allows you to selectively forward the data to specific indexer(s)?
What is the name of the object that stores events inside of an index?
Which of the following must be done to define user permissions when integrating Splunk with LDAP?
A user recently installed an application to index NCINX access logs. After configuring the application, they realize that no data is being ingested. Which configuration file do they need to edit to ingest the access logs to ensure it remains unaffected after upgrade?
How do you remove missing forwarders from the Monitoring Console?
A company moves to a distributed architecture to meet the growing demand for the use of Splunk. What parameter can be configured to enable automatic load balancing in the
Universal Forwarder to send data to the indexers?
A request has been made to restrict lookup files up to 500 megabytes for replication. Anything larger should not be replicated. Which of the following parameters provides the correct control for this scenario?
Which option on the Add Data menu is most useful for testing data ingestion without creating inputs.conf?
What is the correct order of index time precedence?
(For each of the following, highest precedence is shown at the top and lowest precedence is shown at the bottom)
What is the correct example to redact a plain-text password from raw events?
