Splunk SPLK-1003 - Splunk Enterprise Certified Admin
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
Which of the following are reasons to create separate indexes? (Choose all that apply.)
The following stanzas in inputs. conf are currently being used by a deployment client:
[udp: //145.175.118.177:1001
Connection_host = dns
sourcetype = syslog
Which of the following statements is true of data that is received via this input?
Load balancing on a Universal Forwarder is not scaling correctly. The forwarder ' s outputs. and the tcpout stanza are setup correctly. What else could be the cause of this scaling issue? (select all that apply)
What is the valid option for a [monitor] stanza in inputs.conf?
What options are available when creating custom roles? (select all that apply)
Which of the following statements accurately describes using SSL to secure the feed from a forwarder?
How often does Splunk recheck the LDAP server?
There is a file with a vast amount of old data. Which of the following inputs.conf attributes would allow an admin to monitor the file for updates without indexing the pre-existing data?
Which setting in indexes. conf allows data retention to be controlled by time?
