ExamGecko
Question list
Search
Search

List of questions

Search

Question 49 - SPLK-2002 discussion

Report
Export

Which Splunk internal index contains license-related events?

A.

_audit

Answers
A.

_audit

B.

_license

Answers
B.

_license

C.

_internal

Answers
C.

_internal

D.

_introspection

Answers
D.

_introspection

Suggested answer: C

Explanation:

The _internal index contains license-related events, such as the license usage, the license quota, the license pool, the license stack, and the license violations. These events are logged by the license manager in the license_usage.log file, which is part of the _internal index. The _audit index contains audit events, such as user actions, configuration changes, and search activity. These events are logged by the audit trail in the audit.log file, which is part of the _audit index. The _license index does not exist in Splunk, as the license-related events are stored in the _internal index. The _introspection index contains platform instrumentation data, such as the resource usage, the disk objects, the search activity, and the data ingestion. These data are logged by the introspection generator in various log files, such as resource_usage.log, disk_objects.log, search_activity.log, and data_ingestion.log, which are part of the _introspection index. For more information, seeAbout Splunk Enterprise loggingand [About the _internal index] in the Splunk documentation.

asked 13/11/2024
Pamela Joanne Ang
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first