Sign In
Home/Splunk/SPLK-1003/Free questions

SPLK-1003 — Free Practice Questions

10 free sample questions from a bank of 255, with the correct answers and explanations. No signup required — start practising right now.

1Which setting in indexes.conf allows data retention to be controlled by time?
  • maxDaysToKeep
  • moveToFrozenAfter
  • maxDataRetentionTime
  • frozenTimePeriodInSecs
Answer: D
2Where should apps be located on the deployment server that the clients pull from?
  • $SPLUNK_HOME/etc/apps
  • $SPLUNK_HOME/etc/search
  • $SPLUNK_HOME/etc/master-apps
  • $SPLUNK_HOME/etc/deployment-apps
Answer: D
3Using SEDCMD in props.conf allows raw data to be modified. With the given event below, which option will mask the first three digits of the AcctID field resulting output: [22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309 Event: [22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
  • SEDCMD-1acct = s/VendorID=\d{3}(\d{4})/VendorID=xxx/g
  • SEDCMD-xxxAcct = s/AcctID=\d{3}(\d{4})/AcctID=xxx/g
  • SEDCMD-1acct = s/AcctID=\d{3}(\d{4})/AcctID=\1xxx/g
  • SEDCMD-1acct = s/AcctID=\d{3}(\d{4})/AcctID=xxx\1/g
Answer: D
4Which of the following accurately describes HTTP Event Collector indexer acknowledgement?
  • It requires a separate channel provided by the client.
  • It is configured the same as indexer acknowledgement used to protect in-flight data.
  • It can be enabled at the global setting level.
  • It stores status information on the Splunk server.
Answer: A
5What action is required to enable forwarder management in Splunk Web?
  • Navigate to Settings > Server Settings > General Settings, and set an App server port.
  • Navigate to Settings > Forwarding and receiving, and click on Enable Forwarding.
  • Create a server class and map it to a client in SPLUNK_HOME/etc/system/local/serverclass.conf.
  • Place an app in the SPLUNK_HOME/etc/deployment-apps directory of the deployment server.
Answer: D
6Which of the following is accurate regarding the input phase?
  • Breaks data into events with timestamps.
  • Applies event-level transformations.
  • Fine-tunes metadata.
  • Performs character encoding.
Answer: D
7When indexing a data source, which fields are considered metadata?
  • source, host, time
  • time, sourcetype, source
  • host, raw, sourcetype
  • sourcetype, source, host
Answer: D
8What is the default value of LINE_BREAKER?
  • \r\n
  • ([\r\n]+)
  • \r+\n+
  • (\r\n+)
Answer: B
9Which of the following monitor inputs stanza headers would match all of the following files? /var/log/www1/secure.log /var/log/www/secure.l /var/log/www/logs/secure.logs /var/log/www2/secure.log
  • [monitor:///var/log/.../secure.*]
  • [monitor:///var/log/www1/secure.*]
  • [monitor:///var/log/www1/secure.log]
  • [monitor:///var/log/www/secure.]
Answer: A
10What are the values for host and index for [stanza1] used by Splunk during index time, given the following configuration files?
SPLK-1003 question 10
  • host=server1 index=unixinfo
  • host=server1 index=searchinfo
  • host=searchsvr1 index=searchinfo
  • host=unixsvr1 index=unixinfo
Answer: B

Want the full bank of 255 questions for SPLK-1003? See all practice exams.