ExamGecko
Question list
Search
Search

List of questions

Search

Question 17 - SPLK-1005 discussion

Report
Export

When monitoring directories that contain mixed file types, which setting should be omitted from inputs, conf and instead be overridden in propo.conf?

A.

sourcetype

Answers
A.

sourcetype

B.

host

Answers
B.

host

C.

source

Answers
C.

source

D.

index

Answers
D.

index

Suggested answer: A

Explanation:

When monitoring directories containing mixed file types, the sourcetype should typically be overridden in props.conf rather than defined in inputs.conf. This is because sourcetype is meant to classify the type of data being ingested, and when dealing with mixed file types, setting a single sourcetype in inputs.conf would not be effective for accurate data classification. Instead, you can use props.conf to define rules that apply different sourcetypes based on the file path, file name patterns, or other criteria. This allows for more granular and accurate assignment of sourcetypes, ensuring the data is properly parsed and indexed according to its type.

Splunk Cloud

Reference: For further clarification, refer to Splunk's official documentation on configuring inputs and props, especially the sections discussing monitoring directories and configuring sourcetypes.

Source:

Splunk Docs: Monitor files and directories

Splunk Docs: Configure event line breaking and input settings with props.conf

asked 10/10/2024
Jonathan Steeman
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first