Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Splunk SPLK-1005 - Splunk Cloud Certified Admin

Page: 1 / 3
Total 80 questions

When using Splunk Universal Forwarders, which of the following is true?

A.

No more than six Universal Forwarders may connect directly to Splunk Cloud.

B.

Any number of Universal Forwarders may connect directly to Splunk Cloud.

C.

Universal Forwarders must send data to an Intermediate Forwarder.

D.

There must be one Intermediate Forwarder for every three Universal Forwarders.

A monitor has been created in inputs. con: for a directory that contains a mix of file types.

How would a Cloud Admin fine-tune assigned sourcetypes for different files in the directory during the input phase?

A.

On the Indexer parsing the data, leave sourcetype as automatic for the directory monitor. Then create a props.conf that assigns a specific sourcetype by source stanza.

B.

On the forwarder collecting the data, leave sourcetype as automatic for the directory monitor. Then create a props. conf that assigns a specific sourcetype by source stanza.

C.

On the Indexer parsing the data, set multiple sourcetype_source attributes for the directory monitor collecting the files. Then create a props, com that filters out unwanted files.

D.

On the forwarder collecting the data, set multiple 3ourcotype_sourc« attributes for the directory monitor collecting the files. Then create a props. conf that filters out unwanted files.

When monitoring directories that contain mixed file types, which setting should be omitted from inputs, conf and instead be overridden in propo.conf?

A.

sourcetype

B.

host

C.

source

D.

index

Which of the following are default Splunk Cloud user roles?

A.

must_delete, power, sc_admin

B.

power, user, admin

C.

apps, power, sc_admin

D.

can delete, users, admin

Which file or folder below is not a required part of a deployment app?

A.

app.conf (in default or local)

B.

local.meta

C.

metadata folder

D.

props.conf

What can be used in a Splunk Cloud environment to create new sourcetypes?

A.

Data Preview

B.

props. conf can be edited directly from the GUI

C.

Splunk's CLI

D.

Deployment Server

Which of the following statements is true regarding sedcmd?

A.

SEDCMD can be defined in either props.conf or transforms.conf.

B.

SEDCMD does not work on Windows-based installations of Splunk.

C.

SEDCMD uses the same syntax as Splunk's replace command.

D.

SEDCMD provides search and replace functionality using regular expressions and substitutions.

Which of the following tasks is the responsibility of a Splunk Cloud administrator?

A.

Configuring deployer

B.

Configuring cluster master

C.

Configuring indexers

D.

Configuring indexes

Which of the following are features of a managed Splunk Cloud environment?

A.

Availability of premium apps, no IP address whitelisting or blacklisting, deployed in US East AWS region.

B.

20GB daily maximum data ingestion, no SSO integration, no availability of premium apps.

C.

Availability of premium apps, SSO integration, IP address whitelisting and blacklisting.

D.

Availability of premium apps, SSO integration, maximum concurrent search limit of 20.

Which of the following is a valid method to test if a forwarder can successfully send data to Splunk Cloud?

A.

Search the _audit index to confirm whether the forwarder ID was registered.

B.

Use oneshot from the CLI on the forwarders, then check to see if those logs show up in the Splunk Cloud environment.

C.

On Splunk Cloud UI, click Add Data and upload a test file, then search to see if the logs show up.

D.

Ping the inputssl.example.splunkcloud.com to see if it returns the ping.