ExamGecko
Question list
Search
Search

List of questions

Search

Question 44 - SPLK-1005 discussion

Report
Export

Which of the following is an accurate statement about the delete command?

A.

The delete command removes events from disk.

Answers
A.

The delete command removes events from disk.

B.

By default, only admins can run the delete command.

Answers
B.

By default, only admins can run the delete command.

C.

Events are virtually deleted by marking them as deleted.

Answers
C.

Events are virtually deleted by marking them as deleted.

D.

Deleting events reclaims disk space.

Answers
D.

Deleting events reclaims disk space.

Suggested answer: C

Explanation:

The delete command in Splunk does not remove events from disk but rather marks them as 'deleted' in the index. This means the events are not accessible via searches, but they still occupy space on disk. Only users with the can_delete capability (typically admins) can use the delete command.

Splunk Documentation

Reference: Delete Command

asked 10/10/2024
Priya Ketkar
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first