Free SPLK-1003 Exam Braindumps

User role inheritance allows what to be inherited from the parent role? (Select all that apply.)

  1. Parents
  2. Capabilities
  3. Index access
  4. Search history

Answer(s): B


Reference:

https://docs.splunk.com/Documentation/Splunk/7.3.1/Security/Aboutusersandroles#How_users_inherit_capabilities



Which of the following statements apply to directory inputs? (Select all that apply.)

  1. All discovered text files are consumed.
  2. Compressed files are ignored by default.
  3. Splunk recursively traverses through the directory structure.
  4. When adding new log files to a monitored directory, the forwarder must be restarted to take them into account.

Answer(s): C


Reference:

https://answers.splunk.com/answers/133875/recursive-monitoring-of-directories.html



How would you configure your distsearch.conf to allow you to run the search below?
sourcetype=access_combined status=200 action=purchase splunk_server_group=HOUSTON

  1. [distributedSearch:NYC]
    default = false
    servers = nyc1:8089, nyc2:8089
    [distributedSearch:HOUSTON]
    default = false
    servers = houston1:8089, houston2:8089
  2. [distributedSearch]
    servers =nyc1, nyc2, houston1, houston2
    [distributedSearch:NYC]
    default = false
    servers = nyc1, nyc2
    [distributedSearch:HOUSTON]
    default = false
    servers = houston1, houston2
  3. [distributedSearch]
    servers =nyc1:8089, nyc2:8089, houston1:8089, houston2:8089
    [distributedSearch:NYC]
    default = false
    servers = nyc1:8089, nyc2:8089
    [distributedSearch:HOUSTON]
    default = false
    servers = houston1:8089, houston2:8089
  4. [distributedSearch]
    servers =nyc1:8089; nyc2:80893; houston1:8089; houston2:8089
    [distributedSearch:NYC]
    default = false
    servers = nyc1:8089; nyc2:8089
    [distributedSearch:HOUSTON]
    default = false
    servers = houston1:80897706; houston2:80898350

Answer(s): D



Which of the following is a valid distributed search group?

  1. [distributedSearch:Paris]
    default = false
    servers = server1, server2
  2. [searchGroup:Paris]
    default = false
    servers = server1:8089, server2:8089
  3. [searchGroup:Paris]
    default = false
    servers = server1:9997, server2:9997
  4. [distributedSearch:Paris]
    default = false
    servers = server1:8089; server2:8089

Answer(s): D


Reference:

https://docs.splunk.com/Documentation/Splunk/7.3.1/DistSearch/Distributedsearchgroups






Post your Comments and Discuss Splunk® SPLK-1003 exam with other Community members:

SPLK-1003 Exam Discussions & Posts