List of questions
Related questions
Question 161 - SPLK-1003 discussion
A security team needs to ingest a static file for a specific incident. The log file has not been collected previously and future updates to the file must not be indexed.
Which command would meet these needs?
A.
splunk add one shot / opt/ incident [data .log ---index incident
B.
splunk edit monitor /opt/incident/data.* ---index incident
C.
splunk add monitor /opt/incident/data.log ---index incident
D.
splunk edit oneshot [opt/ incident/data.* ---index incident
Your answer:
0 comments
Sorted by
Leave a comment first