Splunk Enterprise Certified Admin Questions and Answers
What are the minimum required settings when creating a network input in Splunk?
What is the command to reset the fishbucket for one source?
Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
Which of the following authentication types requires scripting in Splunk?
A configuration file in a deployed app needs to be directly edited. Which steps would ensure a successful deployment to clients?
In a distributed environment, which Splunk component is used to distribute apps and configurations to the
other Splunk instances?
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?
When does a warm bucket roll over to a cold bucket?
Which of the following configuration files are used with a universal forwarder? (Choose all that apply.)
What is the name of the object that stores events inside of an index?
Which of the following is accurate regarding the input phase?
In this example, ifuseACKis set to true and themaxQueueSizeis set to 7MB, what is the size of the wait queue on this universal forwarder?
In which phase do indexed extractions in props.conf occur?
During search time, which directory of configuration files has the highest precedence?
What is the valid option for a [monitor] stanza in inputs.conf?
Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?
Which Splunk component performs indexing and responds to search requests from the search head?
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs
the following search over the last 24 hours:
index=*
What field can the administrator check to see the data distribution?
In which Splunk configuration is the SEDCMD used?
Which of the following types of data count against the license daily quota?
Which of the following is an appropriate description of a deployment server in a non-cluster environment?
Which additional component is required for a search head cluster?
Using the CLI on the forwarder, how could the current forwarder to indexer configuration be viewed?
Which of the following describes a Splunk deployment server?
Which artifact is required in the request header when creating an HTTP event?
Which of the following Splunk components require a separate installation package?
Who provides the Application Secret, Integration, and Secret keys, as well as the API Hostname when setting
up Duo for Multi-Factor Authentication in Splunk Enterprise?
What is the correct example to redact a plain-text password from raw events?
Which of the following are supported options when configuring optional network inputs?
A company moves to a distributed architecture to meet the growing demand for the use of Splunk. What parameter can be configured to enable automatic load balancing in the
Universal Forwarder to send data to the indexers?
An organization wants to collect Windows performance data from a set of clients, however, installing Splunk
software on these clients is not allowed. What option is available to collect this data in Splunk Enterprise?
Which Splunk configuration file is used to enable data integrity checking?
A non-clustered Splunk environment has three indexers (A,B,C) and two search heads (X, Y). During a search executed on search head X, indexer A crashes. What is Splunk's response?
What is required when adding a native user to Splunk? (select all that apply)
The CLI command splunk add forward-server indexer:
which configuration file?
To set up a Network input in Splunk, what needs to be specified'?
After configuring a universal forwarder to communicate with an indexer, which index can be checked via the Splunk Web UI for a successful connection?
Which of the following enables compression for universal forwarders in outputs. conf ?
A)
B)
C)
D)
Which setting allows the configuration of Splunk to allow events to span over more than one line?
Which feature of Splunk’s role configuration can be used to aggregate multiple roles intended for groups of
users?
Which Splunk component(s) would break a stream of syslog inputs into individual events? (select all that apply)
You update a props. conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btoo1 props list —debug. What will the output be?
Which valid bucket types are searchable? (select all that apply)
Which option accurately describes the purpose of the HTTP Event Collector (HEC)?
UsingSEDCMDinprops.confallows raw data to be modified. With the given event below, which option will mask the first three digits of theAcctIDfield resulting output:[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Event:
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
When working with an indexer cluster, what changes with the global precedence when comparing to a standalone deployment?
Assume a file is being monitored and the data was incorrectly indexed to an exclusive index. The index is
cleaned and now the data must be reindexed. What other index must be cleaned to reset the input checkpoint
information for that file?
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?
Syslog files are being monitored on a Heavy Forwarder.
Where would the appropriate TRANSFORMS setting be deployed to reroute logs based on the event message?
An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data
is 300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the
index?
Immediately after installation, what will a Universal Forwarder do first?
What event-processing pipelines are used to process data for indexing? (select all that apply)
When using license pools, volume allocations apply to which Splunk components?