ExamGecko
Home Home / Splunk / SPLK-1003

SPLK-1003: Splunk Enterprise Certified Admin

Splunk Enterprise Certified Admin
Vendor:

Splunk

Splunk Enterprise Certified Admin Exam Questions: 185
Splunk Enterprise Certified Admin   2.370 Learners
Take Practice Tests
Comming soon
PDF | VPLUS
This study guide should help you understand what to expect on the exam and includes a summary of the topics the exam might cover and links to additional resources. The information and materials in this document should help you focus your studies as you prepare for the exam.

Related questions

In a customer managed Splunk Enterprise environment, what is the endpoint URI used to collect data?

Become a Premium Member for full access
Unlock Premium Member  Unlock Premium Member

Using SEDCMD in props.conf allows raw data to be modified. With the given event below, which option will mask the first three digits of the AcctID field resulting output: [22/Oct/2018:15:50:21]

VendorID=1234 Code=B AcctID=xxx5309

Event:

[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309

A.
SEDCMD-1acct = s/VendorID=\d{3}(\d{4})/VendorID=xxx/g
A.
SEDCMD-1acct = s/VendorID=\d{3}(\d{4})/VendorID=xxx/g
Answers
B.
SEDCMD-xxxAcct = s/AcctID=\d{3}(\d{4})/AcctID=xxx/g
B.
SEDCMD-xxxAcct = s/AcctID=\d{3}(\d{4})/AcctID=xxx/g
Answers
C.
SEDCMD-1acct = s/AcctID=\d{3}(\d{4})/AcctID=\1xxx/g
C.
SEDCMD-1acct = s/AcctID=\d{3}(\d{4})/AcctID=\1xxx/g
Answers
D.
SEDCMD-1acct = s/AcctID=\d{3}(\d{4})/AcctID=xxx\1/g
D.
SEDCMD-1acct = s/AcctID=\d{3}(\d{4})/AcctID=xxx\1/g
Answers
Suggested answer: D

Explanation:

https://docs.splunk.com/Documentation/Splunk/8.2.2/Data/Anonymizedata

Scrolling down to the section titled "Define the sed script in props.conf shows the correct syntax of an example which validates that the number/character /1 immediately preceded the /g

asked 23/09/2024
souhaib chabchoub
37 questions

Which of the following statements describe deployment management? (select all that apply)

A.
Requires an Enterprise license
A.
Requires an Enterprise license
Answers
B.
Is responsible for sending apps to forwarders.
B.
Is responsible for sending apps to forwarders.
Answers
C.
Once used, is the only way to manage forwarders
C.
Once used, is the only way to manage forwarders
Answers
D.
Can automatically restart the host OS running the forwarder.
D.
Can automatically restart the host OS running the forwarder.
Answers
Suggested answer: A, B

Explanation:

https://docs.splunk.com/Documentation/Splunk/8.2.2/Admin/Distdeploylicenses#:~:text=License%2 0requirements,do%20not%20index%20external%20data.

"All Splunk Enterprise instances functioning as management components needs access to an Enterprise license. Management components include the deployment server, the indexer cluster manager node, the search head cluster deployer, and the monitoring console."

https://docs.splunk.com/Documentation/Splunk/8.2.2/Updating/Aboutdeploymentserver

"The deployment server is the tool for distributing configurations, apps, and content updates to groups of Splunk Enterprise instances."

asked 23/09/2024
ABCO TECHNOLOGY
32 questions

Which is a valid stanza for a network input?

A.
[udp://172.16.10.1:9997]connection = dnssourcetype = dns
A.
[udp://172.16.10.1:9997]connection = dnssourcetype = dns
Answers
B.
[any://172.16.10.1:10001]connection_host = ipsourcetype = web
B.
[any://172.16.10.1:10001]connection_host = ipsourcetype = web
Answers
C.
[tcp://172.16.10.1:9997]connection_host = websourcetype = web
C.
[tcp://172.16.10.1:9997]connection_host = websourcetype = web
Answers
D.
[tcp://172.16.10.1:10001]connection_host = dnssourcetype = dns
D.
[tcp://172.16.10.1:10001]connection_host = dnssourcetype = dns
Answers
Suggested answer: D

Explanation:

https://docs.splunk.com/Documentation/Splunk/8.1.1/Data/Monitornetworkports

Reference: https://docs.splunk.com/Documentation/SplunkCloud/8.0.2006/Data/Bypassautomaticsourcetypeassignment

asked 23/09/2024
Alberto Castillo
35 questions

What are the minimum required settings when creating a network input in Splunk?

A.
Protocol, port number
A.
Protocol, port number
Answers
B.
Protocol, port, location
B.
Protocol, port, location
Answers
C.
Protocol, username, port
C.
Protocol, username, port
Answers
D.
Protocol, IP. port number
D.
Protocol, IP. port number
Answers
Suggested answer: A

Explanation:

https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/Inputsconf

[tcp://<remote server>:<port>]

*Configures the input to listen on a specific TCP network port.

*If a <remote server> makes a connection to this instance, the input uses this stanza to configure itself.

*If you do not specify <remote server>, this stanza matches all connections on the specified port.

*Generates events with source set to "tcp:<port>", for example: tcp:514

*If you do not specify a sourcetype, generates events with sourcetype set to "tcp-raw"

asked 23/09/2024
Jarrell John Garcia
37 questions

Consider the following stanza in inputs.conf:

What will the value of the source filed be for events generated by this scripts input?

A.
/opt/splunk/ecc/apps/search/bin/liscer.sh
A.
/opt/splunk/ecc/apps/search/bin/liscer.sh
Answers
B.
unknown
B.
unknown
Answers
C.
liscer
C.
liscer
Answers
D.
liscer.sh
D.
liscer.sh
Answers
Suggested answer: A

Explanation:

https://docs.splunk.com/Documentation/Splunk/8.2.2/Admin/Inputsconf

-Scroll down to source = <string>

*Default: the input file path

asked 23/09/2024
Instel SL
28 questions

Local user accounts created in Splunk store passwords in which file?

A.
$ SFLUNK_HOME/etc/passwd
A.
$ SFLUNK_HOME/etc/passwd
Answers
B.
$ SFLUNK_HOME/etc/authentication
B.
$ SFLUNK_HOME/etc/authentication
Answers
C.
$ S?LUNK_HOME/etc/users/passwd.conf
C.
$ S?LUNK_HOME/etc/users/passwd.conf
Answers
D.
$ SPLUNK HOME/etc/users/authentication.conf
D.
$ SPLUNK HOME/etc/users/authentication.conf
Answers
Suggested answer: A

Explanation:

Per the provided reference URL https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/Userseedconf "To set the default username and password, place user-seed.conf in $SPLUNK_HOME/etc/system/local. You must restart Splunk to enable configurations. If the $SPLUNK_HOME/etc/passwd file is present, the settings in this file (user-seed.conf) are not used."

asked 23/09/2024
Selladurai Ravi
42 questions

Running this search in a distributed environment:

On what Splunk component does the eval command get executed?

Become a Premium Member for full access
Unlock Premium Member  Unlock Premium Member

Which file will be matched for the following monitor stanza in inputs. conf?

Become a Premium Member for full access
Unlock Premium Member  Unlock Premium Member

Within props. conf, which stanzas are valid for data modification? (select all that apply)

A.
Host
A.
Host
Answers
B.
Server
B.
Server
Answers
C.
Source
C.
Source
Answers
D.
Sourcetype
D.
Sourcetype
Answers
Suggested answer: A, C, D

Explanation:

https://docs.splunk.com/Documentation/Splunk/8.0.4/Admin/Propsconf#props.conf.spec

https://docs.splunk.com/Documentation/Splunk/8.1.1/Admin/Propsconf

"* Reuse of the same field-extracting regular expression across multiple sources, source types, or hosts." https://docs.splunk.com/Documentation/Splunk/8.0.4/Admin/Propsconf#props.conf.spec

asked 23/09/2024
Michel Flipse
41 questions