Filters
Question type

Study Flashcards

How do you remove missing forwarders from the Monitoring Console?


A) By restarting Splunk.
B) By rescanning active forwarders.
C) By reloading the deployment server.
D) By rebuilding the forwarder asset table.

E) B) and D)
F) A) and D)

Correct Answer

verifed

verified

Which of the following are supported options when configuring optional network inputs?


A) Metadata override, sender filtering options, network input queues (quantum queues)
B) Metadata override, sender filtering options, network input queues (memory/persistent queues)
C) Filename override, sender filtering options, network output queues (memory/persistent queues)
D) Metadata override, receiver filtering options, network input queues (memory/persistent queues)

E) C) and D)
F) A) and B)

Correct Answer

verifed

verified

Which of the following must be done to define user permissions when integrating Splunk with LDAP?


A) Map Users
B) Map Groups
C) Map LDAP Inheritance
D) Map LDAP to Active Directory

E) All of the above
F) None of the above

Correct Answer

verifed

verified

When deploying apps, which attribute in the forwarder management interface determines the apps that clients install?


A) App Class
B) Client Class
C) Server Class
D) Forwarder Class

E) A) and D)
F) A) and C)

Correct Answer

verifed

verified

Which of the following are methods for adding inputs in Splunk? (Choose all that apply.)


A) CLI
B) Splunk Web
C) Editing inpits.conf Editing inpits.conf
D) Editing monitor.conf monitor.conf

E) A) and C)
F) C) and D)

Correct Answer

verifed

verified

Which layers are involved in Splunk configuration file layering? (Choose all that apply.)


A) App context
B) User context
C) Global context
D) Forwarder context

E) A) and B)
F) A) and D)

Correct Answer

verifed

verified

In which Splunk configuration is the SEDCMD used?


A) props.conf
B) inputs.conf
C) indexes.conf
D) transforms.conf

E) A) and D)
F) B) and D)

Correct Answer

verifed

verified

With authentication methods are natively supported within Splunk Enterprise? (Select all that apply.)


A) LDAP
B) SAML
C) RADIUS
D) Duo Multifactor Authentication

E) A) and B)
F) B) and D)

Correct Answer

verifed

verified

What is the valid option for a [monitor] stanza in inputs.conf ?


A) enabled
B) datasource
C) server_name
D) ignoreOlderThan

E) None of the above
F) All of the above

Correct Answer

verifed

verified

Which Splunk component consolidates the individual results and prepares reports in a distributed environment?


A) Indexers
B) Forwarder
C) Search head
D) Search peers

E) A) and B)
F) A) and C)

Correct Answer

verifed

verified

How is data handled by Splunk during the input phase of the data ingestion process?


A) Data is treated as streams.
B) Data is broken up into events.
C) Data is initially written to disk.
D) Data is measured by the license meter.

E) All of the above
F) A) and D)

Correct Answer

verifed

verified

If an update is made to an attribute in inputs.conf on a universal forwarder, on which Splunk component would the fishbucket need to be reset in order to reindex the data?


A) Indexer
B) Forwarder
C) Search head
D) Deployment server

E) None of the above
F) B) and C)

Correct Answer

verifed

verified

An organization wants to collect Windows performance data from a set of clients, however, installing Splunk software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?


A) Use Local Windows host monitoring.
B) Use Windows Remote Inputs with WMI.
C) Use Local Windows network monitoring.
D) Use an index with an Index Data Type of Metrics.

E) None of the above
F) A) and B)

Correct Answer

verifed

verified

In a distributed environment, which Splunk component is used to distribute apps and configurations to the other Splunk instances?


A) Indexer
B) Deployer
C) Forwarder
D) Deployment server

E) A) and D)
F) B) and D)

Correct Answer

verifed

verified

Which of the following are supported configuration methods to add inputs on a forwarder? (Select all that apply.)


A) CLI
B) Edit inputs.conf Edit inputs.conf
C) Edit forwarder.conf forwarder.conf
D) Forwarder Management

E) None of the above
F) C) and D)

Correct Answer

verifed

verified

In case of a conflict between a whitelist and a blacklist input setting, which one is used?


A) Blacklist
B) Whitelist
C) They cancel each other out.
D) Whichever is entered into the configuration first.

E) All of the above
F) A) and B)

Correct Answer

verifed

verified

Which Splunk component requires a Forwarder license?


A) Search head
B) Heavy forwarder
C) Heaviest forwarder
D) Universal forwarder

E) All of the above
F) None of the above

Correct Answer

verifed

verified

How does the Monitoring Console monitor forwarders?


A) By pulling internal logs from forwarders.
B) By using the forwarder monitoring add-on.
C) With internal logs forwarded by forwarders.
D) With internal logs forwarded by deployment server.

E) A) and B)
F) None of the above

Correct Answer

verifed

verified

Which Splunk component performs indexing and responds to search requests from the search head?


A) Forwarder
B) Search peer
C) License master
D) Search head cluster

E) C) and D)
F) B) and C)

Correct Answer

verifed

verified

An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data is 300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the index?


A) Buy a bigger Splunk license.
B) Add 2.5 TB each day for the next 5 days.
C) Add all 10 TB in a single 24 hour period.
D) Add 200 GB of historical data each day for 50 days.

E) None of the above
F) A) and B)

Correct Answer

verifed

verified

Showing 21 - 40 of 84

Related Exams

Show Answer