ExamGecko
Question list
Search
Search

List of questions

Search

Question 50 - SPLK-1005 discussion

Report
Export

In what scenarios would transforms.conf be used?

A.

Per-Event Index Routing, Applying Event Types, SEOCMD operations

Answers
A.

Per-Event Index Routing, Applying Event Types, SEOCMD operations

B.

Per-Event Sourcetype, Per-Event Host Name, Per-Event Index Routing

Answers
B.

Per-Event Sourcetype, Per-Event Host Name, Per-Event Index Routing

C.

Per-Event Host Name, Per-Event Index Rooting, SEDCMD operations

Answers
C.

Per-Event Host Name, Per-Event Index Rooting, SEDCMD operations

D.

Per-Event Sourcetype, Per-Event Index Routing, Applying Event Types

Answers
D.

Per-Event Sourcetype, Per-Event Index Routing, Applying Event Types

Suggested answer: B

Explanation:

transforms.conf is used for various advanced data processing tasks in Splunk, including:

Per-Event Sourcetype: Dynamically assigning a sourcetype based on event content.

Per-Event Host Name: Dynamically setting the host field based on event content.

Per-Event Index Routing: Directing specific events to different indexes based on their content.

Option B correctly identifies these common uses of transforms.conf.

Splunk Documentation

Reference: transforms.conf - Configuration

asked 10/10/2024
Rick James
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first