Splunk Cloud Certified Admin Questions and Answers
For the following data, what would be the correct attribute/value oair to use to successfully extract the correct timestamp from all the events?
When creating a new index, which of the following is true about archiving expired events?
Where is the recommended place to deploy input apps that are not permitted on Splunk Cloud?
What Splunk command will allow an administrator to view the runtime configuration instructions for a monitored file in Inputs. cont on the forwarders?
When a forwarder phones home to a Deployment Server it compares the check-sum value of the forwarder's app to the Deployment Server's app. What happens to the app If the check-sum values do not match?
In which of the following situations should Splunk Support be contacted?
Which of the following is a valid stanza in props. conf?
Which of the following are valid settings for file and directory monitor inputs?
A)
B)
C)
D)
Which of the following tasks is the responsibility of a Splunk Cloud administrator?
A customer wants to mask unstructured data before sending it to Splunk Cloud. Where should SEBCMD be configured for this?
In what scenarios would transforms.conf be used?
Which of the following is not a path used by Splunk to execute scripts?
Which of the following is true when using Intermediate Forwarders?
When is data deleted from a Splunk Cloud index?
What is the recommended method to test the onboarding of a new data source before putting it in production?
What is the correct syntax to monitor /apache/too/logo, /apache/bor/logs, and /apache/bar/l/logo?
A)
B)
C)
D)
Which of the following is true when integrating LDAP authentication?
Given the following set of files, which of the monitor stanzas below will result in Splunk monitoring all of the files ending with .log?
Files:
/var/log/www1/secure.log
/var/log/www1/access.log
/var/log/www2/logs/secure.log
/var/log/www2/access.log
/var/log/www2/access.log.1
Which of the following is not considered a best practice for the deployment server?
Files from multiple systems are being stored on a centralized log server. The files are organized into directories based on the original server they came from. Which of the following is a recommended approach for correctly setting the host values based on their origin?
Which of the following is an accurate statement about the delete command?
A Splunk Cloud administrator is looking to allow a new group of Splunk users in the marketing department to access the Splunk environment and view a dashboard with relevant data. These users need to access marketing data (stored in the marketing_data index), but shouldn't be able to access other data, such as events related to security or operations.
Which approach would be the best way to accomplish these requirements?
When should Splunk Cloud Support be contacted?
What is the name of the Splunk index that contains the most valuable information for troubleshooting a Splunk issue?