Free SPLK-1003 Exam Braindumps (page: 15)

Page 14 of 35

In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?

  1. To ensure that hot buckets are still open for writers and have not been forced to roll to a cold state.
  2. To ensure that configuration files have not been tampered with for auditing and/or legal purposes.
  3. To ensure that user passwords have not been tampered with for auditing and/or legal purposes.
  4. To ensure that data has not been tampered with for auditing and/or legal purposes.

Answer(s): D


Reference:

https://www.splunk.com/blog/2015/10/28/data-integrity-is-back-baby.html



Which Splunk component performs indexing and responds to search requests from the search head?

  1. Forwarder
  2. Search peer
  3. License master
  4. Search head cluster

Answer(s): B


Reference:

https://www.edureka.co/blog/splunk-architecture/



When deploying apps, which attribute in the forwarder management, interface determines the apps that clients install?

  1. App Class
  2. Client Class
  3. Server Class
  4. Forwarder Class

Answer(s): C


Reference:

https://docs.splunk.com/Documentation/Splunk/7.3.1/Updating/Createdeploymentapps



In this sourcetype definition the MAX_TIMESTAMP_LOOKAHEAD is missing. Which value would fit best?

[sshd_syslog]
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%d %H:%M:%S.%3N %z
LINE_BREAKER = ([\r\n]+)\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}
SHOULD_LINEMERGE = false
TRUNCATE = 0

Event example:
2018-04-13 13:42:41.214 -0500 server sshd[26219]: Connection from 172.0.2.60 port 47366

  1. MAX_TIMESTAMP_LOOKAHEAD=5
  2. MAX_TIMESTAMP_LOOKAHEAD=10
  3. MAX_TIMESTAMP_LOOKAHEAD=20
  4. MAX_TIMESTAMP_LOOKAHEAD=30

Answer(s): B






Post your Comments and Discuss Splunk® SPLK-1003 exam with other Community members:

SPLK-1003 Exam Discussions & Posts