What is the default character encoding used by Splunk during the input phase?
Answer : A
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.1/Data/Configurecharactersetencoding
Which of the following enables compression for universal forwarders in outputs.conf?
Answer : B
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/Outputsconf
User role inheritance allows what to be inherited from the parent role? (Choose all that apply.)
Answer : B
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.1/Security/Aboutusersandroles#How_users_inherit_capabilities
Which of the following statements apply to directory inputs? (Choose all that apply.)
Answer : C
Reference:
https://answers.splunk.com/answers/133875/recursive-monitoring-of-directories.html
How would you configure your distsearch.conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_server_group=HOUSTON
Answer : B
Which of the following is a valid distributed search group?
Answer : D
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.1/DistSearch/Distributedsearchgroups
Local user accounts created in Splunk store passwords in which file?
Answer : A
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/User-seedconf
For single line event sourcetypes, it is most efficient to set SHOULD_LINEMERGE to what value?
Answer : B
Reference:
https://answers.splunk.com/answers/704533/what-are-the-best-practices-for-defining-source-ty.html
Which Splunk component does a search head primarily communicate with?
Answer : A
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.1/InheritedDeployment/Deploymenttopology
Which layers are involved in Splunk configuration file layering? (Choose all that apply.)
Answer : ABC
Which of the following are methods for adding inputs in Splunk? (Choose all that apply.)
Answer : AB
Reference:
http://dev.splunk.com/view/dev-guide/SP-CAAAE3A
Which of the following authentication types requires scripting in Splunk?
Answer : D
Reference:
https://answers.splunk.com/answers/131127/scripted-authentication.html
Which option accurately describes the purpose of the HTTP Event Collector (HEC)?
Answer : B
Reference:
http://dev.splunk.com/view/event-collector/SP-CAAAE6M
What is the difference between the two wildcards ... and * for the monitor stanza in inputs.conf?
Answer : C
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Data/Specifyinputpathswithwildcards
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
Answer : B
Reference:
https://answers.splunk.com/answers/581441/how-is-the-splunk-license-measured.html
Have any questions or issues ? Please dont hesitate to contact us