Splunk Enterprise Certified Admin (SPLK-1003) Free Practice Test
Question 1
Load balancing on a Universal Forwarder is not scaling correctly. The forwarder's outputs. and the tcpout stanza are setup correctly. What else could be the cause of this scaling issue? (select all that apply)
Correct Answer: A,D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 2
An index stores its data in buckets. Which default directories does Splunk use to store buckets?
(Choose all that apply.)
(Choose all that apply.)
Correct Answer: A,C
Question 3
What is a role in Splunk? (select all that apply)
Correct Answer: A,C
Question 4
During search time, which directory of configuration files has the highest precedence?
Correct Answer: C
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 5
An admin is configuring a Universal Forwarder and runs the following command:
splunk add forward-server 10.1.2.3:9997
Following this action, to what index are the Splunk logs sent?
splunk add forward-server 10.1.2.3:9997
Following this action, to what index are the Splunk logs sent?
Correct Answer: A
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 6
After an Enterprise Trial license expires, it will automatically convert to a Free license. How many days is an Enterprise Trial license valid before this conversion occurs?
Correct Answer: D
Question 7
For single line event sourcetypes. it is most efficient to set SHOULD_linemerge to what value?
Correct Answer: B
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 8
Using SEDCMD in props.conf allows raw data to be modified. With the given event below, which option will mask the first three digits of the AcctID field resulting output:
Event:
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Event:
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Correct Answer: B
Question 9
Windows can prevent a Splunk forwarder from reading open files. If files need to be read while they are being written to, what type of input stanza needs to be created?
Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 10
Which of the following is an acceptable channelvalue when using the HTTP Event Collector indexer acknowledgement capability?
Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).