Which optional configuration setting in inputs .conf allows you to selectively forward the data to specific indexer(s)?
Which of the following are methods for adding inputs in Splunk? (select all that apply)
A log file contains 193 days worth of timestamped events. Which monitor stanza would be used to collect data 45 days old and newer from that log file?
When configuring HTTP Event Collector (HEC) input, how would one ensure the events have been indexed?
When running the command shown below, what is the default path in which deployment server. conf is created?
splunk set deploy-poll deployServer:port