Question 1

Which of the following are reasons to create separate indexes? (Choose all that apply.)

Answer : A, D

Question 2

In this example, if useACK is set to true and the maxQueueSize is set to 7MB, what is the size of the wait queue on this universal forwarder?

Answer : A

Question 3

Which setting allows the configuration of Splunk to allow events to span over more than one line?

Answer : C

Question 4

Consider the following stanza in inputs.conf:

What will the value of the source filed be for events generated by this scripts input?

Answer : A

Question 5

What happens when the same username exists in Splunk as well as through LDAP?

Answer : C

Question 6

After automatic load balancing is enabled on a forwarder, the time interval for switching indexers can be updated by using which of the following attributes?

Answer : C

Question 7

The LINE_BREAKER attribute is configured in which configuration file?

Answer : A

