00:00

QUESTION 1

Which of the following are methods for adding inputs in Splunk? (Select all that apply.)

Correct Answer: AB
Reference: http://dev.splunk.com/view/dev -guide/SP-CAAAE3A

QUESTION 2

Which Splunk component does a search head primarily communicate with?

Correct Answer: A
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/InheritedDeployment/Deploymenttopology

QUESTION 3

What type of data is counted against the Enterprise license at a fixed 150 bytes per event?

Correct Answer: B
Reference: https://answers.splunk.com/answers/581441/how-is-the-splunk-license-measured.html

QUESTION 4

How often does Splunk recheck the LDAP server?

Correct Answer: D
Reference: http://docshare02.docshare.tips/files/22651/226514302.pdf

QUESTION 5

Which Splunk forwarder type allows parsing of data before forwarding to an indexer?

Correct Answer: C
Reference: https://docs.splunk.com/Documentation/SplunkCloud/7.2.6/Forwarding/Typesofforwarders