📘 Free SPLK-1003 Sample Questions
Which setting in indexes. conf allows data retention to be controlled by time?
A
maxDaysToKeep
B
moveToFrozenAfter
C
maxDataRetentionTime
D
frozenTimePeriodlnSecs
Correct Answer:
D. frozenTimePeriodlnSecs
Explanation:
https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setaretirementandarchivingpolicy
The universal forwarder has which capabilities when sending data? (select all that apply)
A
Sending alerts
B
Compressing data
C
Obfuscating/hiding data
D
Indexer acknowledgement
Correct Answer:
B. Compressing data
Explanation:
https://docs.splunk.com/Documentation/Splunk/8.0.1/Forwarding/Aboutforwardingandreceivingdat
a
https://docs.splunk.com/Documentation/Forwarder/8.1.1/Forwarder/Configureforwardingwithoutp
uts.conf#:~:text=compressed%3Dtrue%20This%20tells%20the,the%20forwarder%20sends%20raw%
20data.
In case of a conflict between a whitelist and a blacklist input setting, which one is used?
A
Blacklist
B
Whitelist
C
They cancel each other out.
D
Whichever is entered into the configuration first.
Correct Answer:
A. Blacklist
Explanation:
https://docs.splunk.com/Documentation/Splunk/8.0.4/Data/Whitelistorblacklistspecificincomingdat
a
"It is not necessary to define both an allow list and a deny list in a configuration stanza. The settings
are independent. If you do define both filters and a file matches them both, Splunk Enterprise does
not index that file, as the blacklist filter overrides the whitelist filter." Source:
https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/Whitelistorblacklistspecificincomingdat
a
In which Splunk configuration is the SEDCMD used?
A
props, conf
B
inputs.conf
C
indexes.conf
D
transforms.conf
Correct Answer:
A. props, conf
Explanation:
https://docs.splunk.com/Documentation/Splunk/8.0.5/Forwarding/Forwarddatatothird-
partysystemsd
"You can specify a SEDCMD configuration in props.conf to address data that contains characters that
the third-party server cannot process. "
Which of the following are supported configuration methods to add inputs on a forwarder? (select all
that apply)
A
CLI
B
Edit inputs . conf
C
Edit forwarder.conf
D
Forwarder Management
Correct Answer:
A. CLI
Explanation:
https://docs.splunk.com/Documentation/Forwarder/8.2.1/Forwarder/HowtoforwarddatatoSplunkEn
terprise
"You can collect data on the universal forwarder using several methods. Define inputs on the
universal forwarder with the CLI. You can use the CLI to define inputs on the universal forwarder.
After you define the inputs, the universal forwarder collects data based on those definitions as long
as it has access to the data that you want to monitor. Define inputs on the universal forwarder with
configuration files. If the input you want to configure does not have a CLI argument for it, you can
configure inputs with configuration files. Create an inputs.conf file in the directory,
$SPLUNK_HOME/etc/system/loca
Which parent directory contains the configuration files in Splunk?
A
SSFLUNK_HOME/etc
B
SSPLUNK_HOME/var
C
SSPLUNK_HOME/conf
D
SSPLUNK_HOME/default
Correct Answer:
A. SSFLUNK_HOME/etc
Explanation:
https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/Configurationfiledirectories
Section titled, Configuration file directories, states "A detailed list of settings for each configuration
file is provided in the .spec file names for that configuration file. You can find the latest version of the
.spec and .example files in the $SPLUNK_HOME/etc system/README folder of your Splunk Enterprise
installation..."
Which forwarder type can parse data prior to forwarding?
A
Universal forwarder
B
Heaviest forwarder
C
Hyper forwarder
D
Heavy forwarder
Correct Answer:
D. Heavy forwarder
Explanation:
https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Typesofforwarders
"A heavy forwarder parses data before forwarding it and can route data based on criteria such as
SPLK-1003: Actual Exam Q&A | CLEARCATNET
source or type of event."
Which Splunk component consolidates the individual results and prepares reports in a distributed
environment?
A
Indexers
B
Forwarder
C
Search head
D
Search peers
Correct Answer:
C. Search head
Explanation:
https://docs.splunk.com/Documentation/Splunk/7.3.1/DistSearch/Howuserscancontroldistributedse
arches
"From the user standpoint, specifying and running a distributed search is essentially the same as
running any other search. Behind the scenes, the search head distributes the query to its search
peers, and consolidates the results when presenting them to the user."
Which Splunk component distributes apps and certain other configuration updates to search head cluster members?
A
Deployer
B
Cluster master
C
Deployment server
D
Search head cluster master
Correct Answer:
C. Deployment server
Explanation:
https://docs.splunk.com/Documentation/Splunk/8.0.5/Updating/Updateconfigurations First line
says it all: "The deployment server distributes deployment apps to clients."
Where should apps be located on the deployment server that the clients pull from?
A
$SFLUNK_KOME/etc/apps
B
$SPLUNK_HCME/etc/sear:ch
C
$SPLUNK_HCME/etc/master-apps
D
$SPLUNK HCME/etc/deployment-apps
Correct Answer:
D. $SPLUNK HCME/etc/deployment-apps
Explanation:
After an app is downloaded, it resides under $SPLUNK_HOME/etc/apps on the deployment clients.
But it resided in the $SPLUNK_HOME/etc/deployment-apps location in the deployment server.
Questions: 1-10 out of 196
Continue Full Practice..
GET ALL 196 QUESTIONS