ExamGecko
Home / Splunk / SPLK-1003
Ask Question

Splunk SPLK-1003 Practice Test - Questions Answers, Page 19

Question list
Search

Question 181

Report
Export
Collapse

Which pathway represents where a network input in Splunk might be found?

Become a Premium Member for full access
  Unlock Premium Member

Question 182

Report
Export
Collapse

A Universal Forwarder has the following active stanza in inputs . conf:

[monitor: //var/log]

disabled = O

host = 460352847

An event from this input has a timestamp of 10:55. What timezone will Splunk add to the event as part of indexing?

Become a Premium Member for full access
  Unlock Premium Member

Question 183

Report
Export
Collapse

Which scenario is applicable given the stanzas in authentication.conf below?

[authentication]

externalTwoFactorAuthVendor = Duo

externalTwoFactorAuthSettings = duoMFA

[duoMFA]

integrationKey = aGFwcHliaXJ0aGRheU1pZGR5

secretKey = YXVzdHJhaWxpYW5Gb3JHcmVw

applicationKey = c3BsaW5raW5ndGhlcGx1bWJ1c3NpbmN1OTU

apiHostname = 466993018.duosecurity.com

failOpen = True

timeout = 60

Become a Premium Member for full access
  Unlock Premium Member

Question 184

Report
Export
Collapse

Which of the following is a valid method to create a Splunk user?

Become a Premium Member for full access
  Unlock Premium Member

Question 185

Report
Export
Collapse

An admin oversees an environment with a 1000 GBI day license. The configuration file server.conf has strict pool quota=false set. The license is divided into the following three pools, and today's usage is shown on the right-hand column:

Pool License Size Today's usage

X 500 GB/day 100 GB

Y 350 GB/day 400 GB

Z 150 GB/day 300 GB

Given this, which pool(s) are issued warnings?

Become a Premium Member for full access
  Unlock Premium Member

Question 186

Report
Export
Collapse

When enabling data integrity control, where does Splunk Enterprise store the hash files for each bucket?

Become a Premium Member for full access
  Unlock Premium Member

Question 187

Report
Export
Collapse

Which of the following is an acceptable channel value when using the HTTP Event Collector indexer acknowledgment capability?

Become a Premium Member for full access
  Unlock Premium Member

Question 188

Report
Export
Collapse

There is a file with a vast amount of old data. Which of the following inputs.conf attributes would allow an admin to monitor the file for updates without indexing the pre-existing data?

Become a Premium Member for full access
  Unlock Premium Member

Question 189

Report
Export
Collapse

An admin updates the Role to Group mapping for external authentication. How does the change affect users that are currently logged into Splunk?

Become a Premium Member for full access
  Unlock Premium Member
Total 189 questions
Go to page: of 19