Splunk SPLK-1005 Practice Test - Questions Answers, Page 5
List of questions
Related questions
Which of the following is not considered a best practice for the deployment server?
Create small, single-purpose deployment apps.
Dedicate a Splunk instance as the deployment server.
Use a Linux server as the deployment server.
Create large, multi-purpose deployment apps.
When is data deleted from a Splunk Cloud index?
When buckets roll to frozen, without a defined archive.
When data is deleted via the Splunk Cloud Admin GUI.
When TA_Delete is downloaded and enabled from SplunkBase.
When the daleteindex command is executed from the CLI.
What is the recommended method to test the onboarding of a new data source before putting it in production?
Send test data to a test index.
Send data to the associated production index.
Replicate Splunk deployment in a test environment.
Send data to the chance index.
Which of the following is an accurate statement about the delete command?
The delete command removes events from disk.
By default, only admins can run the delete command.
Events are virtually deleted by marking them as deleted.
Deleting events reclaims disk space.
What can be used in a Splunk Cloud environment to create new sourcetypes?
Data Preview
props. conf can be edited directly from the GUI
Splunk's CLI
Deployment Server
Which of the following tasks is the responsibility of a Splunk Cloud administrator?
Configuring deployer
Configuring cluster master
Configuring indexers
Configuring indexes
Which statement is true about monitor inputs?
Monitor inputs are configured in the monitor, conf file.
The ignoreOlderThan option allows files to be ignored based on the file modification time.
The crSalt setting is required.
Monitor inputs can ignore a file's existing content, indexing new data as it arrives, by configuring the tailProcessor option.
Where is the recommended place to deploy input apps that are not permitted on Splunk Cloud?
Universal Forwarder or Heavy Forwarder.
Heavy Forwarder only.
Universal Forwarder only.
Apps cannot be installed on on-prem instances.
For the following data, what would be the correct attribute/value oair to use to successfully extract the correct timestamp from all the events?
TIMK_FORMAT = %b %d %H:%M:%S %z
DATETIME CONFIG = %Y-%m-%d %H:%M:%S %2
TIME_FORMAT = %b %d %H:%M:%S
DATETIKE CONFIG = Sb %d %H:%M:%S
In what scenarios would transforms.conf be used?
Per-Event Index Routing, Applying Event Types, SEOCMD operations
Per-Event Sourcetype, Per-Event Host Name, Per-Event Index Routing
Per-Event Host Name, Per-Event Index Rooting, SEDCMD operations
Per-Event Sourcetype, Per-Event Index Routing, Applying Event Types
Question