ExamGecko
Question list
Search
Search

Question 131 - SPLK-1003 discussion

Report
Export

Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)

A.
props.conf
Answers
A.
props.conf
B.
inputs.conf
Answers
B.
inputs.conf
C.
rawdata.conf
Answers
C.
rawdata.conf
D.
transforms.conf
Answers
D.
transforms.conf
Suggested answer: A, D

Explanation:

https://docs.splunk.com/Documentation/Splunk/8.1.1/Knowledge/Configureadvancedextractionswi thfieldtransforms use transformations with props.conf and transforms.conf to:

– Mask or delete raw data as it is being indexed

–Override sourcetype or host based upon event values

– Route events to specific indexes based on event content

– Prevent unwanted events from being indexed

Reference:

https://docs.splunk.com/Documentation/Splunk/8.0.5/Data/Configuretimestamprecognition

asked 23/09/2024
Junaid Sahebzada
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first