Splunk SPLK-1003 - Splunk Enterprise Certified Admin
What options are available when creating custom roles? (select all that apply)
What is the default character encoding used by Splunk during the input phase?
Which default Splunk role could be assigned to provide users with the following capabilities?
Create saved searches
Edit shared objects and alerts
Not allowed to create custom roles
Which Splunk forwarder type allows parsing of data before forwarding to an indexer?
Which of the following configuration files are used with a universal forwarder? (Choose all that apply.)
What type of Splunk license is pre-selected in a brand new Splunk installation?
Running this search in a distributed environment:
On what Splunk component does the eval command get executed?
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
The following stanza is active in indexes.conf:
[cat_facts]
maxHotSpanSecs = 3600
frozenTimePeriodInSecs = 2630000
maxTota1DataSizeMB = 650000
All other related indexes.conf settings are default values.
If the event timestamp was 3739283 seconds ago, will it be searchable?
When Splunk is integrated with LDAP, which attribute can be changed in the Splunk UI for an LDAP user?