Summer Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the Splunk Enterprise Certified Admin SPLK-1003 Questions and answers with Dumpstech

Exam SPLK-1003 Premium Access

View all detail and faqs for the SPLK-1003 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 7 out of 7 pages
Viewing questions 61-70 out of questions
Questions # 61:

What is the correct attribute to set in inputs.conf in order to have data sent to a particular indexer group?

Options:

A.

_SPLUNKDB_ROUTING

B.

_TCP_ROUTING

C.

_UDF_ROUTING

D.

_INGEST_ROUTING

Questions # 62:

Within props. conf, which stanzas are valid for data modification? (select all that apply)

Options:

A.

Host

B.

Server

C.

Source

D.

Sourcetype

Questions # 63:

Amanda is tasked with hiding the first 5 digits of the account number in the following log and replacing them with xxxxx.

Example events:

[22/Oct/2014:00:46:27] VendorID=9112 Code=B AcctID=4902636940

[22/Oct/2014:00:48:40] VendorID=1004 Code=J AcctID=4236256056

[22/Oct/2014:00:50:02] VendorID=5034 Code=H AcctID=0462999288

Which props.conf configuration would achieve this goal?

Options:

A.

[source::.../vendor_sales.log]

TRANSFORMS-acct = s/AcctID=\d{5}(\d{5})/AcctID=xxxxx\1/g

B.

[source::.../vendor_sales.log]

REPLACE-acct = s/AcctID=\d{5}(\d{5})/AcctID=xxxxx\1/g

C.

[source::.../vendor_sales.log]

SEDCMD-acct = s/AcctID=\d{5}(\d{5})/AcctID=xxxxx\1/g

D.

[source::.../vendor_sales.log]

SED-acct = s/AcctID=\d{5}(\d{5})/AcctID=xxxxx\1/g

Questions # 64:

How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON

A)

B)

Question # 64

C)

Question # 64

D)

Question # 64

Options:

A.

option A

B.

Option B

C.

Option C

D.

Option D

Questions # 65:

Load balancing on a Universal Forwarder is not scaling correctly. The forwarder ' s outputs. and the tcpout stanza are setup correctly. What else could be the cause of this scaling issue? (select all that apply)

Options:

A.

The receiving port is not properly setup to listen on the right port.

B.

The inputs . conf ' S _SYSZOG_ROVTING is not setup to use the right group names.

C.

The DNS record used is not setup with a valid list of IP addresses.

D.

The indexAndForward value is not set properly.

Questions # 66:

An index stores its data in buckets. Which default directories does Splunk use to store buckets? (Choose all that apply.)

Options:

A.

bucketdb

B.

frozendb

C.

colddb

D.

db

Questions # 67:

When running the command shown below, what is the default path in which deployment server. conf is created?

splunk set deploy-poll deployServer:port

Options:

A.

SFLUNK_HOME/etc/deployment

B.

SPLUNK_HOME/etc/system/local

C.

SPLUNK_HOME/etc/system/default

D.

SPLUNK_KOME/etc/apps/deployment

Questions # 68:

What happens when the same username exists in Splunk as well as through LDAP?

Options:

A.

Splunk user is automatically deleted from authentication.conf.

B.

LDAP settings take precedence.

C.

Splunk settings take precedence.

D.

LDAP user is automatically deleted from authentication.conf

Questions # 69:

What is the default purpose of a Splunk Deployment Server ?

Options:

A.

To stage and deploy updates to /etc/pcer-apps/

B.

To stage and deploy updates to $SPLUNK_HOME/etc/apps/

C.

To stage and deploy updates to /etc/manager-apps/

D.

To stage and deploy updates to /etc/deployment-apps/

Questions # 70:

Which optional configuration setting in inputs .conf allows you to selectively forward the data to specific indexer(s)?

Options:

A.

_TCP_ROUTING

B.

_INDEXER_LIST

C.

_INDEXER_GROUP

D.

_INDEXER ROUTING

Viewing page 7 out of 7 pages
Viewing questions 61-70 out of questions