10 free sample questions from a bank of 255, with the correct answers and explanations. No signup required — start practising right now.
1Which setting in indexes.conf allows data retention to be controlled by time?
maxDaysToKeep
moveToFrozenAfter
maxDataRetentionTime
frozenTimePeriodInSecs
Answer: D
2Where should apps be located on the deployment server that the clients pull from?
$SPLUNK_HOME/etc/apps
$SPLUNK_HOME/etc/search
$SPLUNK_HOME/etc/master-apps
$SPLUNK_HOME/etc/deployment-apps
Answer: D
3Using SEDCMD in props.conf allows raw data to be modified. With the given event below, which option will mask the first three digits of the AcctID field resulting output: [22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Event:
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
4Which of the following accurately describes HTTP Event Collector indexer acknowledgement?
It requires a separate channel provided by the client.
It is configured the same as indexer acknowledgement used to protect in-flight data.
It can be enabled at the global setting level.
It stores status information on the Splunk server.
Answer: A
5What action is required to enable forwarder management in Splunk Web?
Navigate to Settings > Server Settings > General Settings, and set an App server port.
Navigate to Settings > Forwarding and receiving, and click on Enable Forwarding.
Create a server class and map it to a client in SPLUNK_HOME/etc/system/local/serverclass.conf.
Place an app in the SPLUNK_HOME/etc/deployment-apps directory of the deployment server.
Answer: D
6Which of the following is accurate regarding the input phase?
Breaks data into events with timestamps.
Applies event-level transformations.
Fine-tunes metadata.
Performs character encoding.
Answer: D
7When indexing a data source, which fields are considered metadata?
source, host, time
time, sourcetype, source
host, raw, sourcetype
sourcetype, source, host
Answer: D
8What is the default value of LINE_BREAKER?
\r\n
([\r\n]+)
\r+\n+
(\r\n+)
Answer: B
9Which of the following monitor inputs stanza headers would match all of the following files?
/var/log/www1/secure.log
/var/log/www/secure.l
/var/log/www/logs/secure.logs
/var/log/www2/secure.log
[monitor:///var/log/.../secure.*]
[monitor:///var/log/www1/secure.*]
[monitor:///var/log/www1/secure.log]
[monitor:///var/log/www/secure.]
Answer: A
10What are the values for host and index for [stanza1] used by Splunk during index time, given the following configuration files?