Splunk SPLK-1003 - Splunk Enterprise Certified Admin
Which default Splunk role could be assigned to provide users with the following capabilities?
Create saved searches
Edit shared objects and alerts
Not allowed to create custom roles
What configuration file are remote Windows Management Instrumentation inputs defined in?
Where can scripts for scripted inputs reside on the host file system? (select all that apply)
In inputs. conf, which stanza would mean Splunk was only reading one local file?
A Splunk administrator has been tasked with developing a retention strategy to have frequently accessed data sets on SSD storage and to have older, less frequently accessed data on slower NAS storage. They have set a mount point for the NAS. Which parameter do they need to modify to set the path for the older, less frequently accessed data in indexes.conf?
TheLINE_BREAKERattribute is configured in which configuration file?
Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as
follows: 123-44-5678.
Which configuration file and stanza pair will mask possible SSNs in the log events?
What is an example of a proper configuration for CHARSET within props.conf?
Which forwarder is recommended by Splunk to use in a production environment?
What is the order of precedence (from lowest → highest) within serverclass.conf in which attributes will be expressed?
