ExamGecko
Question list
Search
Search

List of questions

Search

Question 52 - SPLK-2002 discussion

Report
Export

Which search will show all deployment client messages from the client (UF)?

A.

index=_audit component=DC* host=<ds> | stats count by message

Answers
A.

index=_audit component=DC* host=<ds> | stats count by message

B.

index=_audit component=DC* host=<uf> | stats count by message

Answers
B.

index=_audit component=DC* host=<uf> | stats count by message

C.

index=_internal component= DC* host=<uf> | stats count by message

Answers
C.

index=_internal component= DC* host=<uf> | stats count by message

D.

index=_internal component=DS* host=<ds> | stats count by message

Answers
D.

index=_internal component=DS* host=<ds> | stats count by message

Suggested answer: C

Explanation:

The index=_internal component=DC* host=<uf> search will show all deployment client messages from the universal forwarder. The component field indicates the type of Splunk component that generated the message, and the host field indicates the host name of the machine that sent the message. The index=_audit component=DC* host=<uf> search will not return any results, because the deployment client messages are not stored in the _audit index. The index=_internal component=DS* host=<ds> search will show the deployment server messages from the deployment server, not the client.The index=_audit component=DS* host=<ds> search will also not return any results, for the same reason as above

asked 13/11/2024
Edward Eric
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first