ExamGecko
Question list
Search
Search

Question 148 - SPLK-1003 discussion

Report
Export

In inputs. conf, which stanza would mean Splunk was only reading one local file?

A.
[read://opt/log/crashlog/Jan27crash.txt]
Answers
A.
[read://opt/log/crashlog/Jan27crash.txt]
B.
[monitor::/ opt/log/crashlog/Jan27crash.txt]
Answers
B.
[monitor::/ opt/log/crashlog/Jan27crash.txt]
C.
[monitor:/// opt/log/]
Answers
C.
[monitor:/// opt/log/]
D.
[monitor:/// opt/log/ crashlog/Jan27crash.txt]
Answers
D.
[monitor:/// opt/log/ crashlog/Jan27crash.txt]
Suggested answer: B

Explanation:

[monitor::/opt/log/crashlog/Jan27crash.txt]. This stanza means that Splunk is monitoring a single local file named Jan27crash.txt in the /opt/log/crashlog/ directory1. The monitor input type is used to monitor files and directories for changes and index any new data that is added2.

asked 23/09/2024
Giulia Alberghi
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first