Splunk SPLK-1003 - Splunk Enterprise Certified Admin
The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require
multiple indexers. Following best practices, which types of Splunk component instances are needed?
Which of the following are methods for adding inputs in Splunk? (select all that apply)
Seven different network switches are sending traffic to a server hosting a Universal Forwarder. Three of the devices are sending TCP data and four of the devices are sending UDP data.
What is the minimum number of input stanzas that must be created on the Universal Forwarder to successfully capture data from all seven sources?
Which file will be matched for the following monitor stanza in inputs. conf?
[monitor: ///var/log/*/bar/*. txt]
A user is assigned two roles with the following search filters. What is the user's applied search filter?
Which of the following lists the three phases of the Splunk Indexing process in order?
Which configuration file would be used to forward the Splunk internal logs from a search head to the indexer?
How is data handled by Splunk during the input phase of the data ingestion process?
Which of the following authentication types requires scripting in Splunk?
User role inheritance allows what to be inherited from the parent role? (select all that apply)
