Splunk Enterprise Certified Admin Questions and Answers
Which of the following applies only to Splunk index data integrity check?
Which of the following are methods for adding inputs in Splunk? (select all that apply)
Which of the following monitor inputs stanza headers would match all of the following files?
/var/log/www1/secure.log
/var/log/www/secure.l
/var/log/www/logs/secure.logs
/var/log/www2/secure.log
Where are license files stored?
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
Which of the following is valid distribute search group?
A)
B)
C)
D)
What is required when adding a native user to Splunk? (select all that apply)
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
Which of the following is accurate regarding the input phase?
How does the Monitoring Console monitor forwarders?
When deploying apps, which attribute in the forwarder management interface determines the apps that clients install?
Which of the following must be done to define user permissions when integrating Splunk with LDAP?
Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as
follows: 123-44-5678.
Which configuration file and stanza pair will mask possible SSNs in the log events?
Syslog files are being monitored on a Heavy Forwarder.
Where would the appropriate TRANSFORMS setting be deployed to reroute logs based on the event message?
Which of the following are required when defining an index in indexes. conf? (select all that apply)
Which of the following statements accurately describes using SSL to secure the feed from a forwarder?
Which of the following types of data count against the license daily quota?
In inputs. conf, which stanza would mean Splunk was only reading one local file?
Where can scripts for scripted inputs reside on the host file system? (select all that apply)
Who provides the Application Secret, Integration, and Secret keys, as well as the API Hostname when setting
up Duo for Multi-Factor Authentication in Splunk Enterprise?
Immediately after installation, what will a Universal Forwarder do first?
What are the minimum required settings when creating a network input in Splunk?
The LINE_BREAKER attribute is configured in which configuration file?
An add-on has configured field aliases for source IP address and destination IP address fields. A specific user prefers not to have those fields present in their user context. Based on the default props.conf below, which SPLUNK_HOME/etc/users/buttercup/myTA/local/props.conf stanza can be added to the user’s local context to disable the field aliases?
When enabling data integrity control, where does Splunk Enterprise store the hash files for each bucket?
When using a directory monitor input, specific source type can be selectively overridden using which configuration file?
What conf file needs to be edited to set up distributed search groups?
What is the correct order of steps in Duo Multifactor Authentication?
The CLI command splunk add forward-server indexer:
which configuration file?
What event-processing pipelines are used to process data for indexing? (select all that apply)
What options are available when creating custom roles? (select all that apply)
Windows can prevent a Splunk forwarder from reading open files. If files need to be read while they are being written to, what type of input stanza needs to be created?
In which phase of the index time process does the license metering occur?
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?
What event-processing pipelines are used to process data for indexing? (select all that apply)
A user recently installed an application to index NCINX access logs. After configuring the application, they realize that no data is being ingested. Which configuration file do they need to edit to ingest the access logs to ensure it remains unaffected after upgrade?
Within props. conf, which stanzas are valid for data modification? (select all that apply)
Running this search in a distributed environment:
On what Splunk component does the eval command get executed?
In case of a conflict between a whitelist and a blacklist input setting, which one is used?
What is the command to reset the fishbucket for one source?
Which of the following enables compression for universal forwarders in outputs. conf ?
A)
B)
C)
D)
Which of the following is a benefit of distributed search?
Which Splunk component would one use to perform line breaking prior to indexing?
What is the default value of LINE_BREAKER?
Which of the following methods will connect a deployment client to a deployment server? (select all that apply)
Which of the following statements describe deployment management? (select all that apply)
How is data handled by Splunk during the input phase of the data ingestion process?
When using a directory monitor input, specific source types can be selectively overridden using which configuration file?
Local user accounts created in Splunk store passwords in which file?
Which pathway represents where a network input in Splunk might be found?
Which Splunk component requires a Forwarder license?
What is the correct example to redact a plain-text password from raw events?
What is the correct curl to send multiple events through HTTP Event Collector?
Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?
Event processing occurs at which phase of the data pipeline?
Which option on the Add Data menu is most useful for testing data ingestion without creating inputs.conf?