Splunk SPLK-1005 Practice Test - Questions Answers, Page 4
List of questions
Related questions
In case of a Change Request, which of the following should submit a support case for Splunk Support?
The party requesting the change.
Certified Splunk Cloud administrator.
Splunk infrastructure owner.
Any person with the appropriate entitlement
Consider the following configurations:
What is the value of the sourcetype property for this stanza based on Splunk's configuration file precedence?
NULL, or unset, due to configuration conflict
access_corabined
linux aacurs
linux_secure, access_combined
Which of the following tasks is not managed by the Splunk Cloud administrator?
Forwarding events to Splunk Cloud.
Upgrading the indexer's Splunk software.
Managing knowledge objects.
Creating users and roles.
What is a private app?
An app where only a specific role has read and write access.
An app that is only viewable by a specific user.
An app that is created and used only by a specific organization.
An app where only a specific role has read access.
Which of the following is true when using Intermediate Forwarders?
Intermediate Forwarders may be a mix of Universal and Heavy Forwarders.
All Intermediate Forwarders must be Heavy Forwarders.
Intermediate Forwarders may be Universal Forwarders or Heavy Forwarders, but may not be mixed.
All Intermediate Forwarders must be Universal Forwarders.
When should Splunk Cloud Support be contacted?
For scripted input troubleshooting.
For all configuration changes.
When unable to resolve issues or perform problem isolation.
For resizing, license changes, or any purchases.
Which of the following is a valid stanza in props. conf?
[sourcetype::linux_secure]
[host=nyc25]
[host::nyc*]
[host:nyc*]
When monitoring network inputs, there will be times when the forwarder is unable to send data to the indexers. Splunk uses a memory queue and a disk queue. Which setting is used for the disk queue?
queueSize
maxQeueSize
diskQiioiioiiizo
persistentQueueSize
Which of the following takes place during the input phase?
Splunk annotates data with only 3 metadata keys: host, source, and sourcetype.
Splunk sets the character encoding of the data.
Splunk looks at the contents of the data to apply the correct source.
Splunk breaks data into individual lines.
Which of the following stanzas would enable a TCP input on port 1025, allowing traffic from all IP addresses except 10.5.5.1?
A)
B)
C)
D)
Option A
Option B
Option C
Option D
Question