Which of the following accurately describes HTTP Event Collector indexer acknowledgement?
Who provides the Application Secret, Integration, and Secret keys, as well as the API Hostname when setting
up Duo for Multi-Factor Authentication in Splunk Enterprise?
Which of the following statements accurately describes using SSL to secure the feed from a forwarder?
When working with an indexer cluster, what changes with the global precedence when comparing to a standalone deployment?
Where can scripts for scripted inputs reside on the host file system? (select all that apply)
User role inheritance allows what to be inherited from the parent role? (select all that apply)
A user recently installed an application to index NCINX access logs. After configuring the application, they realize that no data is being ingested. Which configuration file do they need to edit to ingest the access logs to ensure it remains unaffected after upgrade?
How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON
A)

B)

C)

D)

Seven different network switches are sending traffic to a server hosting a Universal Forwarder. Three of the devices are sending TCP data and four of the devices are sending UDP data.
What is the minimum number of input stanzas that must be created on the Universal Forwarder to successfully capture data from all seven sources?
What are the minimum required settings when creating a network input in Splunk?
A Universal Forwarder has the following active stanza in inputs . conf:
[monitor: //var/log]
disabled = O
host = 460352847
An event from this input has a timestamp of 10:55. What timezone will Splunk add to the event as part of indexing?
An admin updates the Role to Group mapping for external authentication. How does the change affect users that are currently logged into Splunk?
A new forwarder has been installed with a manually createddeploymentclient.conf.
What is the next step to enable the communication between the forwarder and the deployment server?
What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?
Within props. conf, which stanzas are valid for data modification? (select all that apply)
Which of the following is an appropriate description of a deployment server in a non-cluster environment?
When enabling data integrity control, where does Splunk Enterprise store the hash files for each bucket?
The following stanzas in inputs. conf are currently being used by a deployment client:
[udp: //145.175.118.177:1001
Connection_host = dns
sourcetype = syslog
Which of the following statements is true of data that is received via this input?
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
Which of the following statements describe deployment management? (select all that apply)
Which of the following indexes come pre-configured with Splunk Enterprise? (select all that apply)
What event-processing pipelines are used to process data for indexing? (select all that apply)
What action could be taken to prevent a license warning with an ingest-based license?
Which Splunk component distributes apps and certain other configuration updates to search head cluster members?
When deploying apps on Universal Forwarders using the deployment server, what is the correct component and location of the app before it is deployed?
Which Splunk component performs indexing and responds to search requests from the search head?
A Universal Forwarder is collecting two separate sources of data (A,B). Source A is being routed through a Heavy Forwarder and then to an indexer. Source B is being routed directly to the indexer. Both sets of data require the masking of raw text strings before being written to disk. What does the administrator need to do to
ensure that the masking takes place successfully?
Which of the following CLI commands removes a search peer from Distributed Search?
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
On the deployment server, administrators can map clients to server classes using client filters. Which of the
following statements is accurate?
When configuring HTTP Event Collector (HEC) input, how would one ensure the events have been indexed?
Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
Which Splunk component(s) would break a stream of syslog inputs into individual events? (select all that apply)
Which setting allows the configuration of Splunk to allow events to span over more than one line?
UsingSEDCMDinprops.confallows raw data to be modified. With the given event below, which option will mask the first three digits of theAcctIDfield resulting output:[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Event:
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Which of the following apply to how distributed search works? (select all that apply)
If an update is made to an attribute in inputs.conf on a universal forwarder, on which Splunk component
would the fishbucket need to be reset in order to reindex the data?
The following stanza is active in indexes.conf:
[cat_facts]
maxHotSpanSecs = 3600
frozenTimePeriodInSecs = 2630000
maxTota1DataSizeMB = 650000
All other related indexes.conf settings are default values.
If the event timestamp was 3739283 seconds ago, will it be searchable?
Which of the following configuration files are used with a universal forwarder? (Choose all that apply.)
When running a real-time search, search results are pulled from which Splunk component?