Splunk Enterprise Certified Admin Questions and Answers
Which of the following is an appropriate description of a deployment server in a non-cluster environment?
A Universal Forwarder is monitoring a very active syslog stream and as a result is unable to switch between destinations. How would an admin safely remediate this issue?
How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON
A)

B)

C)

D)

What action could be taken to prevent a license warning with an ingest-based license?
Which of the following types of data count against the license daily quota?
When would the following command be used?
What is the default purpose of a Splunk Deployment Server?
An admin updates the Role to Group mapping for external authentication. How does the change affect users that are currently logged into Splunk?
After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?
How can native authentication be disabled in Splunk?
Which setting allows the configuration of Splunk to allow events to span over more than one line?
Which valid bucket types are searchable? (select all that apply)
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
In this example, ifuseACKis set to true and themaxQueueSizeis set to 7MB, what is the size of the wait queue on this universal forwarder?
Search heads in a company's European offices need to be able to search data in their New York offices. They also need to restrict access to certain indexers. What should be configured to allow this type of action?
Given a forwarder with the following outputs.conf configuration:
[tcpout : mypartner]
Server = 145.188.183.184:9097
[tcpout : hfbank]
server = inputsl . mysplunkhfs . corp : 9997 , inputs2 . mysplunkhfs . corp : 9997
Which of the following is a true statement?
What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?
What is the valid option for a [monitor] stanza in inputs.conf?
Which additional component is required for a search head cluster?
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
Which of the following are methods for adding inputs in Splunk? (select all that apply)
Which of the following is accurate regarding the input phase?
An index stores its data in buckets. Which default directories does Splunk use to store buckets? (Choose all that apply.)
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?
A log file contains 193 days worth of timestamped events. Which monitor stanza would be used to collect data 45 days old and newer from that log file?
A security team needs to ingest a static file for a specific incident. The log file has not been collected previously and future updates to the file must not be indexed.
Which command would meet these needs?
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs
the following search over the last 24 hours:
index=*
What field can the administrator check to see the data distribution?
There is a file with a vast amount of old data. Which of the following inputs.conf attributes would allow an admin to monitor the file for updates without indexing the pre-existing data?
UsingSEDCMDinprops.confallows raw data to be modified. With the given event below, which option will mask the first three digits of theAcctIDfield resulting output:[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Event:
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Which pathway represents where a network input in Splunk might be found?
What is an example of a proper configuration for CHARSET within props.conf?
The following stanzas in inputs. conf are currently being used by a deployment client:
[udp: //145.175.118.177:1001
Connection_host = dns
sourcetype = syslog
Which of the following statements is true of data that is received via this input?
Which authentication methods are natively supported within Splunk Enterprise? (select all that apply)
What is the correct order of index time precedence?
(For each of the following, highest precedence is shown at the top and lowest precedence is shown at the bottom)
Which artifact is required in the request header when creating an HTTP event?
Assume a file is being monitored and the data was incorrectly indexed to an exclusive index. The index is
cleaned and now the data must be reindexed. What other index must be cleaned to reset the input checkpoint
information for that file?
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?
Which of the following CLI commands removes a search peer from Distributed Search?
A configuration file in a deployed app needs to be directly edited. Which steps would ensure a successful deployment to clients?
Which Splunk component performs indexing and responds to search requests from the search head?
Which of the following is the use case for the deployment server feature of Splunk?
Which Splunk forwarder type allows parsing of data before forwarding to an indexer?
An admin oversees an environment with a 1000 GBI day license. The configuration file
server.conf has strict pool quota=false set. The license is divided into the following three pools, and today's usage is shown on the right-hand column:
PoolLicense SizeToday's usage
X500 GB/day100 GB
Y350 GB/day400 GB
Z150 GB/day300 GB
Given this, which pool(s) are issued warnings?
What is the command to reset the fishbucket for one source?
To set up a Network input in Splunk, what needs to be specified'?
A Splunk administrator has been tasked with developing a retention strategy to have frequently accessed data sets on SSD storage and to have older, less frequently accessed data on slower NAS storage. They have set a mount point for the NAS. Which parameter do they need to modify to set the path for the older, less frequently accessed data in indexes.conf?
Which data pipeline phase is the last opportunity for defining event boundaries?
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
When running the command shown below, what is the default path in which deployment server. conf is created?
splunk set deploy-poll deployServer:port
Which Splunk configuration file is used to enable data integrity checking?
Which of the following enables compression for universal forwarders in outputs. conf ?
A)

B)

C)

D)

What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?
After an Enterprise Trial license expires, it will automatically convert to a Free license. How many days is an Enterprise Trial license valid before this conversion occurs?
What are the values forhostandindexfor[stanza1]used by Splunk during index time, given the following configuration files?

What type of Splunk license is pre-selected in a brand new Splunk installation?
Which of the following is a benefit of distributed search?
If an update is made to an attribute in inputs.conf on a universal forwarder, on which Splunk component
would the fishbucket need to be reset in order to reindex the data?
What action is required to enable forwarder management in Splunk Web?
A new forwarder has been installed with a manually createddeploymentclient.conf.
What is the next step to enable the communication between the forwarder and the deployment server?