ExamGecko
Question list
Search
Search

List of questions

Search

Question 127 - SPLK-2002 discussion

Report
Export

Splunk Enterprise performs a cyclic redundancy check (CRC) against the first and last bytes to prevent the same file from being re-indexed if it is rotated or renamed. What is the number of bytes sampled by default?

A.

128

Answers
A.

128

B.

512

Answers
B.

512

C.

256

Answers
C.

256

D.

64

Answers
D.

64

Suggested answer: C

Explanation:

Splunk Enterprise performs a CRC check against the first and last 256 bytes of a file by default, as stated in theinputs.conf specification. This is controlled by the initCrcLength parameter, which can be changed if needed. The CRC check helps Splunk Enterprise to avoid re-indexing the same file twice, even if it is renamed or rotated, as long as the content does not change. However, this also means that Splunk Enterprise might miss some files that have the same CRC but different content, especially if they have identical headers. To avoid this, the crcSalt parameter can be used to add some extra information to the CRC calculation, such as the full file path or a custom string. This ensures that each file has a unique CRC and is indexed by Splunk Enterprise. You can read more about crcSalt and initCrcLength in theHow log file rotation is handleddocumentation.

asked 13/11/2024
Francisco Jesús Cano Hinarejos
53 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first