How is data handled by Splunk during the input phase of the data ingestion process?
Windows can prevent a Splunk forwarder from reading open files. If files need to be read while they are being written to, what type of input stanza needs to be created?
When deploying apps, which attribute in the forwarder management interface determines the apps that clients install?
Which of the following is the use case for the deployment server feature of Splunk?
An add-on has configured field aliases for source IP address and destination IP address fields. A specific user prefers not to have those fields present in their user context. Based on the defaultprops.confbelow, whichSPLUNK_HOME/etc/users/buttercup/myTA/local/props.confstanza can be added to the user’s local context to disable the field aliases?

Which option accurately describes the purpose of the HTTP Event Collector (HEC)?
Which feature in Splunk allows Event Breaking, Timestamp extractions, and any advanced configurations
found in props.conf to be validated all through the UI?
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?
Consider the following stanza ininputs.conf:
What will the value of the source filed be for events generated by this scripts input?
When Splunk is integrated with LDAP, which attribute can be changed in the Splunk UI for an LDAP user?
Which of the following is an appropriate description of a deployment server in a non-cluster environment?
Which default Splunk role could be assigned to provide users with the following capabilities?
Create saved searches
Edit shared objects and alerts
Not allowed to create custom roles
Amanda is tasked with hiding the first 5 digits of the account number in the following log and replacing them with xxxxx.
Example events:
[22/Oct/2014:00:46:27] VendorID=9112 Code=B AcctID=4902636940
[22/Oct/2014:00:48:40] VendorID=1004 Code=J AcctID=4236256056
[22/Oct/2014:00:50:02] VendorID=5034 Code=H AcctID=0462999288
Which props.conf configuration would achieve this goal?
Which file will be matched for the following monitor stanza in inputs. conf?
[monitor: ///var/log/*/bar/*. txt]
A Splunk administrator has been tasked with developing a retention strategy to have frequently accessed data sets on SSD storage and to have older, less frequently accessed data on slower NAS storage. They have set a mount point for the NAS. Which parameter do they need to modify to set the path for the older, less frequently accessed data in indexes.conf?
A new forwarder has been installed with a manually createddeploymentclient.conf.
What is the next step to enable the communication between the forwarder and the deployment server?
What is the correct order of index time precedence?
(For each of the following, highest precedence is shown at the top and lowest precedence is shown at the bottom)
Which of the following monitor inputs stanza headers would match all of the following files?
/var/log/www1/secure.log
/var/log/www/secure.l
/var/log/www/logs/secure.logs
/var/log/www2/secure.log
In case of a conflict between a whitelist and a blacklist input setting, which one is used?
What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?
Which options for Multifactor Authentication, also known as MFA, are available in Splunk Enterprise?
A Universal Forwarder is collecting two separate sources of data (A,B). Source A is being routed through a Heavy Forwarder and then to an indexer. Source B is being routed directly to the indexer. Both sets of data require the masking of raw text strings before being written to disk. What does the administrator need to do to
ensure that the masking takes place successfully?
After an Enterprise Trial license expires, it will automatically convert to a Free license. How many days is an Enterprise Trial license valid before this conversion occurs?
Assume a file is being monitored and the data was incorrectly indexed to an exclusive index. The index is
cleaned and now the data must be reindexed. What other index must be cleaned to reset the input checkpoint
information for that file?
What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?
What happens when there are conflicting settings within two or more configuration files?
Where should apps be located on the deployment server that the clients pull from?
When working with an indexer cluster, what changes with the global precedence when comparing to a standalone deployment?
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?
In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?
Event example:
Which of the following is true regarding LDAP integration with Splunk Enterprise?
What is the order of precedence (from lowest → highest ) within serverclass.conf in which attributes will be expressed?
When running the command shown below, what is the default path in which deployment server. conf is created?
splunk set deploy-poll deployServer:port