ExamHelpDesk

Complete list of current Q & A>>

Splunk Enterprise Certified Admin (SPLK-1003) – Quiz

1 / 15

Category: Splunk Enterprise Certified Admin (SPLK-1003)

The priority of layered Splunk configuration files depends on the file’s:

2 / 15

Category: Splunk Enterprise Certified Admin (SPLK-1003)

When running the command shown below, what is the default path in which deploymentserver.conf is created? splunk set deploy-poll deployServer:port

3 / 15

Category: Splunk Enterprise Certified Admin (SPLK-1003)

You update a props.conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btool props list `”-debug. What will the output be?

4 / 15

Category: Splunk Enterprise Certified Admin (SPLK-1003)

In which phase of the index time process does the license metering occur?

5 / 15

Category: Splunk Enterprise Certified Admin (SPLK-1003)

This file has been manually created on a universal forwarder:
/opt/splunkforwarder/etc/apps/my_TA/local/inputs.conf
[monitor:///var/log/messages]
sourcetype=syslog
index=syslog
A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new inputs.conf file:
/opt/splunk/etc/deployment-apps/my_TA/local/inputs.conf
[monitor:///var/log/maillog]
sourcetype=maillog
index=syslog
Which file is now monitored?

6 / 15

Category: Splunk Enterprise Certified Admin (SPLK-1003)

Where should apps be located on the deployment server that the clients pull from?

7 / 15

Category: Splunk Enterprise Certified Admin (SPLK-1003)

Which Splunk component distributes apps and certain other configuration updates to search head cluster members?

8 / 15

Category: Splunk Enterprise Certified Admin (SPLK-1003)

Which Splunk component consolidates the individual results and prepares reports in a distributed environment?

9 / 15

Category: Splunk Enterprise Certified Admin (SPLK-1003)

Which forwarder type can parse data prior to forwarding?

10 / 15

Category: Splunk Enterprise Certified Admin (SPLK-1003)

Which parent directory contains the configuration files in Splunk?

11 / 15

Category: Splunk Enterprise Certified Admin (SPLK-1003)

Which of the following are supported configuration methods to add inputs on a forwarder? (Choose all that apply.)

12 / 15

Category: Splunk Enterprise Certified Admin (SPLK-1003)

Which setting in indexes.conf allows data retention to be controlled by time?

13 / 15

Category: Splunk Enterprise Certified Admin (SPLK-1003)

The universal forwarder has which capabilities when sending data? (Choose all that apply.)

14 / 15

Category: Splunk Enterprise Certified Admin (SPLK-1003)

In case of a conflict between a whitelist and a blacklist input setting, which one is used?

15 / 15

Category: Splunk Enterprise Certified Admin (SPLK-1003)

In which Splunk configuration is the SEDCMD used?

Your score is

0%

Scroll to Top