ExamGecko
Question list
Search
Search

List of questions

Search

Question 51 - SPLK-1005 discussion

Report
Export

Which monitor statement will retrieve only files that start with 'access' in the directory /opt/log/ww2/?

A.

[monitor:///opt/lug/.../access]

Answers
A.

[monitor:///opt/lug/.../access]

B.

[monitor:///opt/log/www2/access*]

Answers
B.

[monitor:///opt/log/www2/access*]

C.

[monitor:///opt/log/www2/]

Answers
C.

[monitor:///opt/log/www2/]

D.

[monitor:///opt/log/.../]

Answers
D.

[monitor:///opt/log/.../]

Suggested answer: B

Explanation:

The correct monitor statement to retrieve only files that start with 'access' in the directory /opt/log/www2/ is [monitor:///opt/log/www2/access*]. This configuration specifically targets files that begin with the name 'access' and will match any such files within that directory, such as 'access.log'.

Splunk Documentation

Reference: Monitor files and directories

asked 10/10/2024
Shaharyar Chaudhry
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first