Splunk SPLK-1003 - Splunk Enterprise Certified Admin
A non-clustered Splunk environment has three indexers (A,B,C) and two search heads (X, Y). During a search executed on search head X, indexer A crashes. What is Splunk's response?
Which data pipeline phase is the last opportunity for defining event boundaries?
Which of the following indexes come pre-configured with Splunk Enterprise? (select all that apply)
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
What is the difference between the two wildcards ... and - for the monitor stanza in inputs, conf?
An index stores its data in buckets. Which default directories does Splunk use to store buckets? (Choose all that apply.)
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
On the deployment server, administrators can map clients to server classes using client filters. Which of the
following statements is accurate?
Which of the methods listed below supports muti-factor authentication?
