Splunk Enterprise Certified Admin Questions and Answers
During search time, which directory of configuration files has the highest precedence?
When does a warm bucket roll over to a cold bucket?
Which of the following describes a Splunk deployment server?
An index stores its data in buckets. Which default directories does Splunk use to store buckets? (Choose all that apply.)
Which of the following statements describes how distributed search works?
Which of the following is a benefit of distributed search?
Which of the following accurately describes HTTP Event Collector indexer acknowledgement?
Which of the following is an appropriate description of a deployment server in a non-cluster environment?
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
This file has been manually created on a universal forwarder
A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new

Which file is now monitored?
Which of the following is true regarding LDAP integration with Splunk Enterprise?
Which configuration accepts syslog data over UDP port 514 from all 10.x.x.x hosts except hosts in the 10.1.x.x network?
Which Splunk component would one use to perform line breaking prior to indexing?
Which of the following is an acceptable channel value when using the HTTP Event Collector indexer acknowledgment capability?
Load balancing on a Universal Forwarder is not scaling correctly. The forwarder ' s outputs. and the tcpout stanza are setup correctly. What else could be the cause of this scaling issue? (select all that apply)
Which Splunk component distributes apps and certain other configuration updates to search head cluster members?
To set up a Network input in Splunk, what needs to be specified ' ?
Which option accurately describes the purpose of the HTTP Event Collector (HEC)?
The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require
multiple indexers. Following best practices, which types of Splunk component instances are needed?
Which parent directory contains the configuration files in Splunk?
An admin updates the Role to Group mapping for external authentication. How does the change affect users that are currently logged into Splunk?
Which of the following is a valid method to create a Splunk user?
Which of the methods listed below supports muti-factor authentication?
Which of the following indexes come pre-configured with Splunk Enterprise? (select all that apply)
After configuring a universal forwarder to communicate with an indexer, which index can be checked via the Splunk Web UI for a successful connection?
When running a real-time search, search results are pulled from which Splunk component?
In inputs. conf, which stanza would mean Splunk was only reading one local file?
Which of the following is a valid distributed search group?
Which of the following are supported options when configuring optional network inputs?
Which of the following lists the three phases of the Splunk Indexing process in order?
Which is a valid stanza for a network input?
When indexing a data source, which fields are considered metadata?
After an Enterprise Trial license expires, it will automatically convert to a Free license. How many days is an Enterprise Trial license valid before this conversion occurs?
How can native authentication be disabled in Splunk?
Where are deployment server apps mapped to clients?
What is the correct order of index time precedence?
(For each of the following, highest precedence is shown at the top and lowest precedence is shown at the bottom)
What event-processing pipelines are used to process data for indexing? (select all that apply)
When using a directory monitor input, specific source types can be selectively overridden using which configuration file?
Which of the following are available input methods when adding a file input in Splunk Web? (Choose all that
apply.)
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?
When would the following command be used?
In addition to single, non-clustered Splunk instances, what else can the deployment server push apps to?
In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?
When are knowledge bundles distributed to search peers?
Which of the following statements accurately describes using SSL to secure the feed from a forwarder?
In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?
Event example:
Assume a file is being monitored and the data was incorrectly indexed to an exclusive index. The index is
cleaned and now the data must be reindexed. What other index must be cleaned to reset the input checkpoint
information for that file?
Which of the following enables compression for universal forwarders in outputs. conf ?
A)
B)
C)
D)
A request has been made to restrict lookup files up to 500 megabytes for replication . Anything larger should not be replicated . Which of the following parameters provides the correct control for this scenario?
Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as
follows: 123-44-5678.
Which configuration file and stanza pair will mask possible SSNs in the log events?
Which default Splunk role could be assigned to provide users with the following capabilities?
Create saved searches
Edit shared objects and alerts
Not allowed to create custom roles
When restarting services, the Splunk Enterprise instance reports that there is a “typo in stanza.” Which Splunk command will help locate the error?
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?
Which Splunk configuration file is used to enable data integrity checking?
Which valid bucket types are searchable? (select all that apply)
What is the correct curl to send multiple events through HTTP Event Collector?
Which pathway represents where a network input in Splunk might be found?
How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON
A)
B)

C)

D)

What is the command to reset the fishbucket for one source?
All search-time field extractions should be specified on which Splunk component?
Which Splunk component(s) would break a stream of syslog inputs into individual events? (select all that apply)
Which of the following is true when authenticating users to Splunk using LDAP?
What is the importance of modifying Transparent Huge Pages (THP) and ulimit settings when installing Splunk Enterprise?