Splunk SPLK-1005 Practice Test - Questions Answers, Page 2
List of questions
Related questions
Which of the following app installation scenarios can be achieved without involving Splunk Support?
Deploy premium apps.
Install apps via the Request Install button.
Install apps via self-service.
Install apps that have not gone through the vetting process.
Which file or folder below is not a required part of a deployment app?
app.conf (in default or local)
local.meta
metadata folder
props.conf
Which of the following files is used for both search-time and index-time configuration?
inputs.conf
props.conf
macros.conf
savesearch.conf
What Splunk command will allow an administrator to view the runtime configuration instructions for a monitored file in Inputs. cont on the forwarders?
./splunk _internal call /services/data/input.3/filemonitor
./splunk show config inputs.conf
./splunk _internal rest /services/data/inputs/monitor
./splunk show config inputs
Which of the following lists all parameters supported by the acceptFrom argument?
IPv4, IPv6, CIDRs, DNS names, Wildcards
IPv4, IPv6, CIDRs, DNS names
CIDRs, DNS names, Wildcards
IPv4. CIDRs, DNS names. Wildcards
At what point in the indexing pipeline set is SEDCMD applied to data?
In the aggregator queue
In the parsing queue
In the exec pipeline
In the typing pipeline
When monitoring directories that contain mixed file types, which setting should be omitted from inputs, conf and instead be overridden in propo.conf?
sourcetype
host
source
index
How are HTTP Event Collector (HEC) tokens configured in a managed Splunk Cloud environment?
Any token will be accepted by HEC, the data may just end up in the wrong index.
A token is generated when configuring a HEC input, which should be provided to the application developers.
Obtain a token from the organization's application developers and apply it in Settings > Data Inputs > HTTP Event Collector > New Token.
Open a support case for each new data input and a token will be provided.
Which of the following statements regarding apps in Splunk Cloud is true?
Self-service install of premium apps is possible.
Only Cloud certified and vetted apps are supported.
Any app that can be deployed in an on-prem Splunk Enterprise environment is also supported on Splunk Cloud.
Self-service install is available for all apps on Splunkbase.
When using Splunk Universal Forwarders, which of the following is true?
No more than six Universal Forwarders may connect directly to Splunk Cloud.
Any number of Universal Forwarders may connect directly to Splunk Cloud.
Universal Forwarders must send data to an Intermediate Forwarder.
There must be one Intermediate Forwarder for every three Universal Forwarders.
Question