Winter Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

SPLK-1005 Exam Dumps - Splunk Cloud Certified Admin

Go to page:
Question # 4

The following Apache access log is being ingested into Splunk via a monitor input:

How does Splunk determine the time zone for this event?

A.

The value of the TZ attribute in props. cont for the a :ces3_ccwbined sourcetype.

B.

The value of the TZ attribute in props, conf for the my.webserver.example host.

C.

The time zone of the Heavy/Intermediate Forwarder with the monitor input.

D.

The time zone indicator in the raw event data.

Full Access
Question # 5

Which of the following statements regarding apps in Splunk Cloud is true?

A.

Self-service install of premium apps is possible.

B.

Only Cloud certified and vetted apps are supported.

C.

Any app that can be deployed in an on-prem Splunk Enterprise environment is also supported on Splunk Cloud.

D.

Self-service install is available for all apps on Splunkbase.

Full Access
Question # 6

Which of the following statements is true regarding sedcmd?

A.

SEDCMD can be defined in either props.conf or transforms.conf.

B.

SEDCMD does not work on Windows-based installations of Splunk.

C.

SEDCMD uses the same syntax as Splunk's replace command.

D.

SEDCMD provides search and replace functionality using regular expressions and substitutions.

Full Access
Question # 7

When adding a directory monitor and specifying a sourcetype explicitly, it applies to all files in the directory and subdirectories. If automatic sourcetyping is used, a user can selectively override it in which file on the forwarder?

A.

transforms.conf

B.

props.conf

C.

inputs.conf

D.

outputs.cont

Full Access
Question # 8

When monitoring directories that contain mixed file types, which setting should be omitted from inputs, conf and instead be overridden in propo.conf?

A.

sourcetype

B.

host

C.

source

D.

index

Full Access
Go to page: