Splunk SPLK-1003 Practice Test - Questions Answers, Page 10
List of questions
Question 91
When indexing a data source, which fields are considered metadata?
Question 92
What is the default value of LINE_BREAKER?
Question 93
Which of the following monitor inputs stanza headers would match all of the following files?
/var/log/www1/secure.log
/var/log/www/secure.l
/var/log/www/logs/secure.logs
/var/log/www2/secure.log
Question 94
What are the values for host and index for [stanza1] used by Splunk during index time, given the following configuration files?
Question 95
An index stores its data in buckets. Which default directories does Splunk use to store buckets?
(Choose all that apply.)
Question 96
The LINE_BREAKER attribute is configured in which configuration file?
Question 97
After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?
Question 98
A log file contains 193 days worth of timestamped events. Which monitor stanza would be used to collect data 45 days old and newer from that log file?
Question 99
After an Enterprise Trial license expires, it will automatically convert to a Free license. How many days is an Enterprise Trial license valid before this conversion occurs?
Question 100
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?
Question