Splunk SPLK-1003 Practice Test - Questions Answers, Page 18
List of questions
Question 171
Which of the following describes a Splunk deployment server?
Question 172
What type of Splunk license is pre-selected in a brand new Splunk installation?
Question 173
Given a forwarder with the following outputs.conf configuration:
[tcpout : mypartner]
Server = 145.188.183.184:9097
[tcpout : hfbank]
server = inputsl . mysplunkhfs . corp : 9997 , inputs2 . mysplunkhfs . corp : 9997
Which of the following is a true statement?
Question 174
Search heads in a company's European offices need to be able to search data in their New York offices. They also need to restrict access to certain indexers. What should be configured to allow this type of action?
Question 175
When deploying apps on Universal Forwarders using the deployment server, what is the correct component and location of the app before it is deployed?
Question 176
Windows can prevent a Splunk forwarder from reading open files. If files need to be read while they are being written to, what type of input stanza needs to be created?
Question 177
When should the Data Preview feature be used?
Question 178
Which file will be matched for the following monitor stanza in inputs. conf?
Question 179
Syslog files are being monitored on a Heavy Forwarder.
Where would the appropriate TRANSFORMS setting be deployed to reroute logs based on the event message?
Question 180
Which Splunk component(s) would break a stream of syslog inputs into individual events? (select all that apply)
Question