Splunk SPLK-1001 Practice Test - Questions Answers, Page 16
List of questions
Related questions
You can on-board data to Splunk using following means (Choose four.):
A.
Props
B.
CLI
C.
Splunk Web
D.
savedsearches.conf
E.
Splunk apps and add-ons
F.
indexes.conf
G.
inputs.conf
H.
metadata.conf
Data sources being opened and read applies to:
A.
None of the above
B.
Indexing Phase
C.
Parsing Phase
D.
Input Phase
E.
License Metering
Select the correct option that applies to Index time processing (Choose three.).
A.
Indexing
B.
Searching
C.
Parsing
D.
Settings
E.
Input
Splunk automatically determines the source type for major data types.
A.
False
B.
True
Splunk index time process can be broken down into __________ phases.
A.
3
B.
2
C.
4
D.
1
In monitor option you can select the following options in GUI.
A.
Only HTTP Event Collector (HEC) and TCP/UDP
B.
None of the above
C.
Only TCP/UDP
D.
Only Scripts
E.
Filed & Directories, HTTP Event Collector (HEC), TCP/UDP and Scripts
Uploading local files though Upload options index the file only once.
A.
No
B.
Yes
Where does Licensing meter happen?
A.
Indexer
B.
Parsing
C.
Heavy Forwarder
D.
Input
Question