Black Friday Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

All SPLK-1005 Test Inside Splunk Questions

Page: 6 / 6
Total 80 questions

Splunk Cloud Certified Admin Questions and Answers

Question 21

A log file is being ingested into Splunk, and a few events have no date stamp. How would Splunk first try to determine the missing date of the events?

Options:

A.

Splunk will take the date of a previous event within the log file.

B.

Splunk will use the current system time of the Indexer for the date.

C.

Splunk will use the date of when the file monitor was created.

D.

Splunk will take the date from the file modification time.

Question 22

Which file or folder below is not a required part of a deployment app?

Options:

A.

app.conf (in default or local)

B.

local.meta

C.

metadata folder

D.

props.conf

Question 23

How is it possible to test a script from the Splunk perspective before using it within a scripted input?

Options:

A.

splunk run

B.

splunk script

C.

./$SPLUNK_HOME/etc/apps//bin/

D.

splunk cmd

Question 24

A customer has worked with their LDAP administrator to configure an LDAP strategy in Splunk. The configuration works, and user Mia can log into Splunk using her LDAP Account. After some time, the Splunk Cloud administrator needs to move Mia from the user role to the power role. How should they accomplish this?

Options:

A.

Ask the LDAP administrator to move Mia's account to an appropriately mapped LDAP group.

B.

Have Mia log into Splunk, then update her own role in user settings.

C.

Create a role named Power in Splunk, then map Mia's account to that role.

D.

Use the Cloud Monitoring Console app as an administrator to map Mia's account to the power role.

Page: 6 / 6
Total 80 questions