Splunk SPLK-1003 Practice Test - Questions Answers, Page 4

List of questions
Question 31

Which of the following apply to how distributed search works? (select all that apply)
Users log on to the search head and run reports: β The search head dispatches searches to the peers β Peers run searches in parallel and return their portion of results β The search head consolidates the individual results and prepares reports
Question 32

Which setting in indexes. conf allows data retention to be controlled by time?
https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setaretirementandarchivingpolicy
Question 33

The universal forwarder has which capabilities when sending data? (select all that apply)
https://docs.splunk.com/Documentation/Splunk/8.0.1/Forwarding/Aboutforwardingandreceivingdata
https://docs.splunk.com/Documentation/Forwarder/8.1.1/Forwarder/Configureforwardingwithoutputs.conf#:~:text=compressed%3Dtrue%20This%20tells%20the,the%20forwarder%20sends%20raw%20data.
Question 34

In case of a conflict between a whitelist and a blacklist input setting, which one is used?
https://docs.splunk.com/Documentation/Splunk/8.0.4/Data/Whitelistorblacklistspecificincomingdata "
It is not necessary to define both an allow list and a deny list in a configuration stanza. The settings are independent. If you do define both filters and a file matches them both, Splunk Enterprise does not index that file, as the blacklist filter overrides the whitelist filter." Source:
https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/Whitelistorblacklistspecificincomingdata
Question 35

In which Splunk configuration is the SEDCMD used?
https://docs.splunk.com/Documentation/Splunk/8.0.5/Forwarding/Forwarddatatothirdpartysystemsd
"You can specify a SEDCMD configuration in props.conf to address data that contains characters that the third-party server cannot process. "
Question 36

Which of the following are supported configuration methods to add inputs on a forwarder? (select all that apply)
https://docs.splunk.com/Documentation/Forwarder/8.2.1/Forwarder/HowtoforwarddatatoSplunkEnterprise
"You can collect data on the universal forwarder using several methods. Define inputs on the universal forwarder with the CLI. You can use the CLI to define inputs on the universal forwarder.
After you define the inputs, the universal forwarder collects data based on those definitions as long as it has access to the data that you want to monitor. Define inputs on the universal forwarder with configuration files. If the input you want to configure does not have a CLI argument for it, you can configure inputs with configuration files. Create an inputs.conf file in the directory, $SPLUNK_HOME/etc/system/local
Question 37

Which parent directory contains the configuration files in Splunk?
Question 38

Which forwarder type can parse data prior to forwarding?
Question 39

Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
Question 40

Which Splunk component distributes apps and certain other configuration updates to search head cluster members?
Question