How can event logs be collected from a remote Windows machine using a standard Splunk installation and no customization? (Select all that apply.)
After updating a dashboard in myApp, a Splunk admin moves myApp to a different Splunk instance. After logging in to the new instance, the dashboard is not seen. What could have happened? (Select all that apply.)
Which of the following are true of auto-refresh for dashboard panels? (Select all that apply.)
Which of the following is an example of a valid syntax for specifying an absolute time range modifier in a search?
Which HTTP Event Collector (HEC) endpoint should be used to collect data in the following format?
{“message”:“Hello World”, “foo”:“bar”, “pony”:“buttercup”}
A fellow Splunk administrator is reviewing an app that has been downloaded from splunkbase and deployed in an organization. The admin has e-mailed the following configuration snippet with a brief note that says “fix the permissions”.
In what configuration file should the snippet be placed?
[]
access = read : [ * ], write : [ admin ] export - system
(Assume that $APP_HOME refers to the path that the app is installed, e.g. $SPLUNK_HOME/etc/apps/
Which of the following statements describe an HEC token? (Select all that apply.)
Which statements are true regarding HEC (HTTP Event Collector) tokens? (Select all that apply.)
Which of these URLs could be used to construct a REST request to search the employee KV store collection to find records with a rating greater than or equal to 2 and less than 5?
Which of the following are valid parent elements for the event action shown below? (Select all that apply.)
Which of the following is a way to monitor app performance? (Select all that apply.)
Which of the following are security best practices for Splunk app development? (Select all that apply.)
For a KV store, a lookup stanza in the transforms.conf file must contain which of the following? (Select all that apply.)
When the search/jobs REST endpoint is called to execute a search, what can be done to reduce the results size in the results? (Select all that apply.)