ExamGecko
Question list
Search
Search

List of questions

Search

Question 13 - SPLK-1005 discussion

Report
Export

Which of the following files is used for both search-time and index-time configuration?

A.

inputs.conf

Answers
A.

inputs.conf

B.

props.conf

Answers
B.

props.conf

C.

macros.conf

Answers
C.

macros.conf

D.

savesearch.conf

Answers
D.

savesearch.conf

Suggested answer: B

Explanation:

The props.conf file is a crucial configuration file in Splunk that is used for both search-time and index-time configurations.

At index-time, props.conf is used to define how data should be parsed and indexed, such as timestamp recognition, line breaking, and data transformations.

At search-time, props.conf is used to configure how data should be searched and interpreted, such as field extractions, lookups, and sourcetypes.

B . props.conf is the correct answer because it is the only file listed that serves both index-time and search-time purposes.

Splunk Documentation

Reference:

props.conf - configuration for search-time and index-time

asked 10/10/2024
Maryna Zarytska
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first