Splunk SPLK-1003 - Splunk Enterprise Certified Admin
Which optional configuration setting in inputs .conf allows you to selectively forward the data to specific indexer(s)?
Which command will join a Universal Forwarder to a deployment server?
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
Search heads in a company ' s European offices need to be able to search data in their New York offices. They also need to restrict access to certain indexers. What should be configured to allow this type of action?
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
Which of the following is accurate regarding the input phase?
What will the following inputs. conf stanza do?
[script://myscript . sh]
Interval=0
When Splunk is integrated with LDAP, which attribute can be changed in the Splunk UI for an LDAP user?
A Universal Forwarder is monitoring a very active syslog stream and as a result is unable to switch between destinations. How would an admin safely remediate this issue?
