ExamGecko
Home / Splunk / SPLK-1005 / List of questions
Ask Question

Splunk SPLK-1005 Practice Test - Questions Answers, Page 2

Add to Whishlist

List of questions

Question 11

Report Export Collapse

Which of the following app installation scenarios can be achieved without involving Splunk Support?

Deploy premium apps.

Deploy premium apps.

Install apps via the Request Install button.

Install apps via the Request Install button.

Install apps via self-service.

Install apps via self-service.

Install apps that have not gone through the vetting process.

Install apps that have not gone through the vetting process.

Suggested answer: C
Explanation:

In Splunk Cloud, you can install apps via self-service, which allows you to install certain approved apps without involving Splunk Support. This self-service capability is provided for apps that have already been vetted and approved for use in the Splunk Cloud environment.

Option A typically requires support involvement because premium apps often need licensing or other special considerations.

Option B might involve the Request Install button, but some apps might still require vetting or support approval.

Option D is incorrect because apps that have not gone through the vetting process cannot be installed via self-service and would require Splunk Support for evaluation and approval.

Splunk Documentation

Reference: Install apps on Splunk Cloud

asked 10/10/2024
David Ezejimofor
44 questions

Question 12

Report Export Collapse

Which file or folder below is not a required part of a deployment app?

app.conf (in default or local)

app.conf (in default or local)

local.meta

local.meta

metadata folder

metadata folder

props.conf

props.conf

Suggested answer: D
Explanation:

When creating a deployment app in Splunk, certain files and folders are considered essential to ensure proper configuration and operation:

app.conf (in default or local): This is required as it defines the app's metadata and behaviors.

local.meta: This file is important for defining access permissions for the app and is often included.

metadata folder: The metadata folder contains files like local.meta and default.meta and is typically required for defining permissions and other metadata-related settings.

props.conf: While props.conf is essential for many Splunk apps, it is not mandatory unless you need to define specific data parsing or transformation rules.

D . props.conf is the correct answer because, although it is commonly used, it is not a mandatory part of every deployment app. An app may not need data parsing configurations, and thus, props.conf might not be present in some apps.

Splunk Documentation

Reference:

Building Splunk Apps

Deployment Apps

This confirms that props.conf is not a required part of a deployment app, making it the correct answer.

asked 10/10/2024
Jozsef Stelly
54 questions

Question 13

Report Export Collapse

Which of the following files is used for both search-time and index-time configuration?

inputs.conf

inputs.conf

props.conf

props.conf

macros.conf

macros.conf

savesearch.conf

savesearch.conf

Suggested answer: B
Explanation:

The props.conf file is a crucial configuration file in Splunk that is used for both search-time and index-time configurations.

At index-time, props.conf is used to define how data should be parsed and indexed, such as timestamp recognition, line breaking, and data transformations.

At search-time, props.conf is used to configure how data should be searched and interpreted, such as field extractions, lookups, and sourcetypes.

B . props.conf is the correct answer because it is the only file listed that serves both index-time and search-time purposes.

Splunk Documentation

Reference:

props.conf - configuration for search-time and index-time

asked 10/10/2024
Maryna Zarytska
38 questions

Question 14

Report Export Collapse

What Splunk command will allow an administrator to view the runtime configuration instructions for a monitored file in Inputs. cont on the forwarders?

./splunk _internal call /services/data/input.3/filemonitor

./splunk _internal call /services/data/input.3/filemonitor

./splunk show config inputs.conf

./splunk show config inputs.conf

./splunk _internal rest /services/data/inputs/monitor

./splunk _internal rest /services/data/inputs/monitor

./splunk show config inputs

./splunk show config inputs

Suggested answer: C
Explanation:

To view the runtime configuration instructions for a monitored file in inputs.conf on the forwarder, the correct command to use involves accessing the internal REST API that provides details on data inputs.

C . ./splunk _internal rest /services/data/inputs/monitor is the correct answer. This command uses Splunk's internal REST endpoint to retrieve information about monitored files, including their runtime configurations as defined in inputs.conf.

Splunk Documentation

Reference:

Splunk REST API - Data Inputs

asked 10/10/2024
Mohammad Wahid
51 questions

Question 15

Report Export Collapse

Which of the following lists all parameters supported by the acceptFrom argument?

IPv4, IPv6, CIDRs, DNS names, Wildcards

IPv4, IPv6, CIDRs, DNS names, Wildcards

IPv4, IPv6, CIDRs, DNS names

IPv4, IPv6, CIDRs, DNS names

CIDRs, DNS names, Wildcards

CIDRs, DNS names, Wildcards

IPv4. CIDRs, DNS names. Wildcards

IPv4. CIDRs, DNS names. Wildcards

Suggested answer: B
Explanation:

The acceptFrom parameter is used in Splunk to specify which IP addresses or DNS names are allowed to send data to a Splunk instance. The supported formats include IPv4, IPv6, CIDR notation, and DNS names.

B . IPv4, IPv6, CIDRs, DNS names is the correct answer. These are the valid formats that can be used with the acceptFrom argument. Wildcards are not supported in acceptFrom parameters for security reasons, as they would allow overly broad access.

Splunk Documentation

Reference:

acceptFrom Parameter Usage

asked 10/10/2024
Jarlesi Bolivar
39 questions

Question 16

Report Export Collapse

At what point in the indexing pipeline set is SEDCMD applied to data?

Splunk SPLK-1005 image Question 16 114226 10102024015435000000

Become a Premium Member for full access
  Unlock Premium Member

Question 17

Report Export Collapse

When monitoring directories that contain mixed file types, which setting should be omitted from inputs, conf and instead be overridden in propo.conf?

Become a Premium Member for full access
  Unlock Premium Member

Question 18

Report Export Collapse

How are HTTP Event Collector (HEC) tokens configured in a managed Splunk Cloud environment?

Become a Premium Member for full access
  Unlock Premium Member

Question 19

Report Export Collapse

Which of the following statements regarding apps in Splunk Cloud is true?

Become a Premium Member for full access
  Unlock Premium Member

Question 20

Report Export Collapse

When using Splunk Universal Forwarders, which of the following is true?

Become a Premium Member for full access
  Unlock Premium Member
Total 80 questions
Go to page: of 8