Splunk SPLK-1003 Practice Test - Questions Answers
List of questions
Related questions
Question 1
Which valid bucket types are searchable? (select all that apply)
Explanation:
Hot/warm/cold/thawed bucket types are searchable. Frozen isn't searchable because its either deleted at that state or archived.
Question 2
How do you remove missing forwarders from the Monitoring Console?
Question 3
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
Explanation:
"The forwarder/indexer relationship can be considered platform agnostic (within the sphere of supported platforms) because they exchange their data handshake (and the data, if you wish) over TCP.
Question 4
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
Explanation:
REGEX = <regular expression>
* Enter a regular expression to operate on your data.
FORMAT = <string>
* NOTE: This option is valid for both index-time and search-time field extraction. Index-time field extraction configuration require the FORMAT settings. The FORMAT settings is optional for searchtime field extraction configurations.
* This setting specifies the format of the event, including any field names or values you want to add.
DEST_KEY = <key>
* NOTE: This setting is only valid for index-time field extractions.
* Specifies where SPLUNK software stores the expanded FORMAT results in accordance with the REGEX match.
Question 5
Which of the following indexes come pre-configured with Splunk Enterprise? (select all that apply)
Explanation:
https://docs.splunk.com/Documentation/Splunk/8.0.5/Indexer/Howindexingworks
Question 6
How often does Splunk recheck the LDAP server?
Explanation:
https://docs.splunk.com/Documentation/Splunk/8.0.6/Security/ManageSplunkuserroleswithLDAP
Question 7
Where are license files stored?
Question 8
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
Question 9
Which is a valid stanza for a network input?
Explanation:
https://docs.splunk.com/Documentation/Splunk/8.1.1/Data/Monitornetworkports
Reference: https://docs.splunk.com/Documentation/SplunkCloud/8.0.2006/Data/Bypassautomaticsourcetypeassignment
Question 10
Which additional component is required for a search head cluster?
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.5/DistSearch/SHCdeploymentoverview
The deployer. This is a Splunk Enterprise instance that distributes apps and other configurations to the cluster members. It stands outside the cluster and cannot run on the same instance as a cluster member. It can, however, under some circumstances, reside on the same instance as other Splunk Enterprise components, such as a deployment server or an indexer cluster master node.
Question