Splunk SPLK-1003 - Splunk Enterprise Certified Admin
Which of the following configuration files are used with a universal forwarder? (Choose all that apply.)
When does a warm bucket roll over to a cold bucket?
This file has been manually created on a universal forwarder
A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new

Which file is now monitored?
Which of the following is true when authenticating users to Splunk using LDAP?
In which phase of the index time process does the license metering occur?
What happens when the same username exists in Splunk as well as through LDAP?
Syslog files are being monitored on a Heavy Forwarder.
Where would the appropriate TRANSFORMS setting be deployed to reroute logs based on the event message?
In a distributed environment, which Splunk component is used to distribute apps and configurations to the
other Splunk instances?
Which of the following lists the three phases of the Splunk Indexing process in order?
During search time, which directory of configuration files has the highest precedence?
