11.11 Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

SPLK-1005 Exam Dumps - Splunk Cloud Certified Admin

Question # 4

The following Apache access log is being ingested into Splunk via a monitor input:

How does Splunk determine the time zone for this event?

A.

The value of the TZ attribute in props. cont for the a :ces3_ccwbined sourcetype.

B.

The value of the TZ attribute in props, conf for the my.webserver.example host.

C.

The time zone of the Heavy/Intermediate Forwarder with the monitor input.

D.

The time zone indicator in the raw event data.

Full Access
Question # 5

Which of the following statements regarding apps in Splunk Cloud is true?

A.

Self-service install of premium apps is possible.

B.

Only Cloud certified and vetted apps are supported.

C.

Any app that can be deployed in an on-prem Splunk Enterprise environment is also supported on Splunk Cloud.

D.

Self-service install is available for all apps on Splunkbase.

Full Access
Question # 6

Which of the following statements is true regarding sedcmd?

A.

SEDCMD can be defined in either props.conf or transforms.conf.

B.

SEDCMD does not work on Windows-based installations of Splunk.

C.

SEDCMD uses the same syntax as Splunk's replace command.

D.

SEDCMD provides search and replace functionality using regular expressions and substitutions.

Full Access
Question # 7

When adding a directory monitor and specifying a sourcetype explicitly, it applies to all files in the directory and subdirectories. If automatic sourcetyping is used, a user can selectively override it in which file on the forwarder?

A.

transforms.conf

B.

props.conf

C.

inputs.conf

D.

outputs.cont

Full Access
Question # 8

When monitoring directories that contain mixed file types, which setting should be omitted from inputs, conf and instead be overridden in propo.conf?

A.

sourcetype

B.

host

C.

source

D.

index

Full Access
Question # 9

Which of the following is a valid method to test if a forwarder can successfully send data to Splunk Cloud?

A.

Search the _audit index to confirm whether the forwarder ID was registered.

B.

Use oneshot from the CLI on the forwarders, then check to see if those logs show up in the Splunk Cloud environment.

C.

On Splunk Cloud UI, click Add Data and upload a test file, then search to see if the logs show up.

D.

Ping the inputssl.example.splunkcloud.com to see if it returns the ping.

Full Access
Question # 10

Which of the following is a valid monitor stanza for inputs.conf?

A.

[monitor:///var/log/*.log] index = linux sourcetype = access_combined host = 489307057

B.

[monitor:\\\var\log\httpd-[0-9].log] index = linux sourcetype = access_combined host = 489307057

C.

[monitor:///var/log/httpd-[0-9].log] index = linux sourcetype = access_combined host = 489307057

D.

[monitor:\\\var\log\*.log] index = linux sourcetype = access_combined host = 489307057

Full Access
Question # 11

Which statement is true about monitor inputs?

A.

Monitor inputs are configured in the monitor, conf file.

B.

The ignoreOlderThan option allows files to be ignored based on the file modification time.

C.

The crSalt setting is required.

D.

Monitor inputs can ignore a file's existing content, indexing new data as it arrives, by configuring the tailProcessor option.

Full Access
Question # 12

Which of the following is a correct statement about Universal Forwarders?

A.

The Universal Forwarder must be able to contact the license master.

B.

A Universal Forwarder must connect to Splunk Cloud via a Heavy Forwarder.

C.

A Universal Forwarder can be an Intermediate Forwarder.

D.

The default output bandwidth is 500KBps.

Full Access
Question # 13

Where is the recommended place to deploy input apps that are not permitted on Splunk Cloud?

A.

Universal Forwarder or Heavy Forwarder.

B.

Heavy Forwarder only.

C.

Universal Forwarder only.

D.

Apps cannot be installed on on-prem instances.

Full Access
Question # 14

When should Splunk Cloud Support be contacted?

A.

For scripted input troubleshooting.

B.

For all configuration changes.

C.

When unable to resolve issues or perform problem isolation.

D.

For resizing, license changes, or any purchases.

Full Access
Question # 15

A Splunk Cloud administrator is looking to allow a new group of Splunk users in the marketing department to access the Splunk environment and view a dashboard with relevant data. These users need to access marketing data (stored in the marketing_data index), but shouldn't be able to access other data, such as events related to security or operations.

Which approach would be the best way to accomplish these requirements?

A.

Create a new user with access to the marketing_data index assigned.

B.

Create a new role that inherits the user role and remove the capability to search indexes other than marketing_data.

C.

Create a new role that inherits the admin rote and assign access to the marketing_dat.a index.

D.

Create a new role that does not inherit from any other role, turn on the same capabilities as the user role, and assign access to the marketing_data index.

Full Access
Question # 16

What does the followTail attribute do in inputs.conf?

A.

Pauses a file monitor if the queue is full.

B.

Only creates a tail checkpoint of the monitored file.

C.

Ingests a file starting with new content and then reading older events.

D.

Prevents pre-existing content in a file from being ingested.

Full Access
Question # 17

A customer has worked with their LDAP administrator to configure an LDAP strategy in Splunk. The configuration works, and user Mia can log into Splunk using her LDAP Account. After some time, the Splunk Cloud administrator needs to move Mia from the user role to the power role. How should they accomplish this?

A.

Ask the LDAP administrator to move Mia's account to an appropriately mapped LDAP group.

B.

Have Mia log into Splunk, then update her own role in user settings.

C.

Create a role named Power in Splunk, then map Mia's account to that role.

D.

Use the Cloud Monitoring Console app as an administrator to map Mia's account to the power role.

Full Access
Question # 18

A monitor has been created in inputs. con: for a directory that contains a mix of file types.

How would a Cloud Admin fine-tune assigned sourcetypes for different files in the directory during the input phase?

A.

On the Indexer parsing the data, leave sourcetype as automatic for the directory monitor. Then create a props.conf that assigns a specific sourcetype by source stanza.

B.

On the forwarder collecting the data, leave sourcetype as automatic for the directory monitor. Then create a props. conf that assigns a specific sourcetype by source stanza.

C.

On the Indexer parsing the data, set multiple sourcetype_source attributes for the directory monitor collecting the files. Then create a props, com that filters out unwanted files.

D.

On the forwarder collecting the data, set multiple 3ourcotype_sourc« attributes for the directory monitor collecting the files. Then create a props. conf that filters out unwanted files.

Full Access
Question # 19

Which of the following are features of a managed Splunk Cloud environment?

A.

Availability of premium apps, no IP address whitelisting or blacklisting, deployed in US East AWS region.

B.

20GB daily maximum data ingestion, no SSO integration, no availability of premium apps.

C.

Availability of premium apps, SSO integration, IP address whitelisting and blacklisting.

D.

Availability of premium apps, SSO integration, maximum concurrent search limit of 20.

Full Access
Question # 20

In what scenarios would transforms.conf be used?

A.

Per-Event Index Routing, Applying Event Types, SEOCMD operations

B.

Per-Event Sourcetype, Per-Event Host Name, Per-Event Index Routing

C.

Per-Event Host Name, Per-Event Index Rooting, SEDCMD operations

D.

Per-Event Sourcetype, Per-Event Index Routing, Applying Event Types

Full Access
Question # 21

Which of the following lists all parameters supported by the acceptFrom argument?

A.

IPv4, IPv6, CIDRs, DNS names, Wildcards

B.

IPv4, IPv6, CIDRs, DNS names

C.

CIDRs, DNS names, Wildcards

D.

IPv4. CIDRs, DNS names. Wildcards

Full Access
Question # 22

Given the following set of files, which of the monitor stanzas below will result in Splunk monitoring all of the files ending with .log?

Files:

    /var/log/www1/secure.log

    /var/log/www1/access.log

    /var/log/www2/logs/secure.log

    /var/log/www2/access.log

    /var/log/www2/access.log.1

A.

[monitor:///var/log/*/*.log]

B.

[monitor:///var/log/.../*.log]

C.

[monitor:///var/log/*/*]

D.

[monitor:///var/log/.../*]

Full Access
Question # 23

Due to internal security policies, a Splunk Cloud administrator cannot send data directly to Splunk Cloud from certain data sources. Additional parsing and API-based data sources also need to be sent to Splunk Cloud. What forwarder type should the Splunk Cloud administrator use to satisfy these requirements within their environment?

A.

Syslog-ng server with a universal forwarder

B.

Light forwarder as an intermediate forwarder

C.

Heavy forwarder as an intermediate forwarder

D.

Universal forwarder as an intermediate forwarder

Full Access
Question # 24

When using Splunk Universal Forwarders, which of the following is true?

A.

No more than six Universal Forwarders may connect directly to Splunk Cloud.

B.

Any number of Universal Forwarders may connect directly to Splunk Cloud.

C.

Universal Forwarders must send data to an Intermediate Forwarder.

D.

There must be one Intermediate Forwarder for every three Universal Forwarders.

Full Access