Splunk Enterprise Certified Admin Questions and Answers
Which of the following are reasons to create separate indexes? (Choose all that apply.)
All search-time field extractions should be specified on which Splunk component?
During search time, which directory of configuration files has the highest precedence?
When should the Data Preview feature be used?
Which Splunk component distributes apps and certain other configuration updates to search head cluster members?
In which phase of the index time process does the license metering occur?
Which of the following configuration files are used with a universal forwarder? (Choose all that apply.)
When indexing a data source, which fields are considered metadata?
Which forwarder type can parse data prior to forwarding?
When using a directory monitor input, specific source type can be selectively overridden using which configuration file?
After how many warnings within a rolling 30-day period will a license violation occur with an enforced
Enterprise license?
A Universal Forwarder is collecting two separate sources of data (A,B). Source A is being routed through a Heavy Forwarder and then to an indexer. Source B is being routed directly to the indexer. Both sets of data require the masking of raw text strings before being written to disk. What does the administrator need to do to
ensure that the masking takes place successfully?
Where should apps be located on the deployment server that the clients pull from?
Search heads in a company's European offices need to be able to search data in their New York offices. They also need to restrict access to certain indexers. What should be configured to allow this type of action?
For single line event sourcetypes. it is most efficient to set SHOULD_linemerge to what value?
A Universal Forwarder has the following active stanza in inputs . conf:
[monitor: //var/log]
disabled = O
host = 460352847
An event from this input has a timestamp of 10:55. What timezone will Splunk add to the event as part of indexing?
User role inheritance allows what to be inherited from the parent role? (select all that apply)
In this example, if useACK is set to true and the maxQueueSize is set to 7MB, what is the size of the wait queue on this universal forwarder?
Consider the following stanza in inputs.conf:
What will the value of the source filed be for events generated by this scripts input?
When does a warm bucket roll over to a cold bucket?
Which configuration file would be used to forward the Splunk internal logs from a search head to the indexer?
Which feature in Splunk allows Event Breaking, Timestamp extractions, and any advanced configurations
found in props.conf to be validated all through the UI?
Local user accounts created in Splunk store passwords in which file?
Which is a valid stanza for a network input?
Which artifact is required in the request header when creating an HTTP event?
If an update is made to an attribute in inputs.conf on a universal forwarder, on which Splunk component
would the fishbucket need to be reset in order to reindex the data?
Which of the following applies only to Splunk index data integrity check?
In which phase do indexed extractions in props.conf occur?
Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?
What are the minimum required settings when creating a network input in Splunk?
To set up a Network input in Splunk, what needs to be specified'?
What is the name of the object that stores events inside of an index?
When working with an indexer cluster, what changes with the global precedence when comparing to a standalone deployment?
Which valid bucket types are searchable? (select all that apply)
Which of the following are available input methods when adding a file input in Splunk Web? (Choose all that
apply.)
The LINE_BREAKER attribute is configured in which configuration file?
What will the following inputs. conf stanza do?
[script://myscript . sh]
Interval=0
Which of the following statements describes how distributed search works?
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?
Which Splunk forwarder type allows parsing of data before forwarding to an indexer?
Which authentication methods are natively supported within Splunk Enterprise? (select all that apply)
Which scenario is applicable given the stanzas in authentication.conf below?
[authentication]
externalTwoFactorAuthVendor = Duo
externalTwoFactorAuthSettings = duoMFA
[duoMFA]
integrationKey = aGFwcHliaXJ0aGRheU1pZGR5
secretKey = YXVzdHJhaWxpYW5Gb3JHcmVw
applicationKey = c3BsaW5raW5ndGhlcGx1bWJ1c3NpbmN1OTU
apiHostname = 466993018.duosecurity.com
failOpen = True
timeout = 60
You update a props. conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btoo1 props list —debug. What will the output be?
After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?
In which Splunk configuration is the SEDCMD used?
What event-processing pipelines are used to process data for indexing? (select all that apply)
Which of the following methods will connect a deployment client to a deployment server? (select all that apply)
What is the default value of LINE_BREAKER?
In a distributed environment, which Splunk component is used to distribute apps and configurations to the
other Splunk instances?
Which setting in indexes. conf allows data retention to be controlled by time?
In case of a conflict between a whitelist and a blacklist input setting, which one is used?
A new forwarder has been installed with a manually created deploymentclient.conf.
What is the next step to enable the communication between the forwarder and the deployment server?
What is a role in Splunk? (select all that apply)
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
An add-on has configured field aliases for source IP address and destination IP address fields. A specific user prefers not to have those fields present in their user context. Based on the default props.conf below, which SPLUNK_HOME/etc/users/buttercup/myTA/local/props.conf stanza can be added to the user’s local context to disable the field aliases?