Q1. Which search head cluster component is responsible for pushing knowledge bundles to search peers, replicating configuration changes to search head cluster members, and scheduling jobs across the search head cluster?
A.Master
B. Captain
C. Deployer
D. Deployment server
Correct Answer: B
Q2. A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)
A.The field was extracted as a private knowledge object.
B. The events are tagged as communicate, but are missing the network tag.
C. The Typing Queue, which does regular expression replacements, is blocked.
D. The colleague did not explicitly use the field in the search and the search was set to Fast Mode.
Correct Answer: A, D
Q3. Which of the following is a valid use case that a search head cluster addresses?
A.Provide redundancy in the event a search peer fails.
B. Search affinity.
C. Knowledge Object replication.
D. Increased Search Factor (SF).
Correct Answer: C
Q4. Which instance can not share functionality with the deployer?
A.Search head cluster member
B. License master
C. Master node
D. Monitoring Console (MC)
Correct Answer: B
Q5. As of Splunk 9.0, which index records changes to . conf files?
A._configtracker
B. _introspection
C. _internal
D. _audit
Correct Answer: A
$ 39
Reviews
There are no reviews yet.