Q1. A monitor has been created in inputs. con: for a directory that contains a mix of file types. How would a Cloud Admin fine-tune assigned sourcetypes for different files in the directory during the input phase?
A.On the Indexer parsing the data, leave sourcetype as automatic for the directory monitor. Then create a props.conf that assigns a specific sourcetype by source stanza.
B. On the forwarder collecting the data, leave sourcetype as automatic for the directory monitor. Then create a props. conf that assigns a specific sourcetype by source stanza.
C. On the Indexer parsing the data, set multiple sourcetype_source attributes for the directory monitor collecting the files. Then create a props, com that filters out unwanted files.
D. On the forwarder collecting the data, set multiple 3ourcotype_sourc attributes for the directory monitor collecting the files. Then create a props. conf that filters out unwanted files.
Correct Answer: B
Q2. Which of the following files is used for both search-time and index-time configuration?
A.inputs.conf
B. props.conf
C. macros.conf
D. savesearch.conf
Correct Answer: B
Q3. Which of the following statements is true about data transformations using SEDCMD?
A.Can only be used to mask or truncate raw data.
B. Configured in props.conf and transform.conf.
C. Can be used to manipulate the sourcetype per event.
D. Operates on a REGEX pattern match of the source, sourcetype, or host of an event.
Correct Answer: A
Q4. Which of the following files is used for both search-time and index-time configuration?
A.inputs.conf
B. props.conf
C. macros.conf
D. savesearch.conf
Correct Answer: B
Q5. Given the following set of files, which of the monitor stanzas below will result in Splunk monitoring all of the files ending with .log? Files: /var/log/www1/secure.log /var/log/www1/access.log /var/log/www2/logs/secure.log /var/log/www2/access.log /var/log/www2/access.log.1
A.[monitor:///var/log/*/*.log]
B. [monitor:///var/log/.../*.log]
C. [monitor:///var/log/*/*]
D. [monitor:///var/log/.../*]
Correct Answer: B
$ 39
Reviews
There are no reviews yet.