Splunk Enterprise Certified Admin SPLK-1003 Exam Practice Test

Page: 1 / 14
Total 196 questions
Question 1

Which of the following statements describes how distributed search works?



Answer : C

URL https://docs.splunk.com/Documentation/Splunk/8.2.2/DistSearch/Configuredistributedsearch

'To activate distributed search, you add search peers, or indexers, to a Splunk Enterprise instance that you desingate as a search head. You do this by specifying each search peer manually.'


Question 2

Which configuration file would be used to forward the Splunk internal logs from a search head to the indexer?



Answer : C

https://docs.splunk.com/Documentation/Splunk/8.1.1/DistSearch/Forwardsearchheaddata

Per the provided Splunk reference URL by @hwangho, scroll to section Forward search head data, subsection titled, 2. Configure the search head as a forwarder. 'Create an outputs.conf file on the search head that configures the search head for load-balanced forwarding across the set of search peers (indexers).'


Question 3

Which option on the Add Data menu is most useful for testing data ingestion without creating inputs.conf?



Answer : A


Question 4
Question 5

Which additional component is required for a search head cluster?



Answer : A


The deployer. This is a Splunk Enterprise instance that distributes apps and other configurations to the cluster members. It stands outside the cluster and cannot run on the same instance as a cluster member. It can, however, under some circumstances, reside on the same instance as other Splunk Enterprise components, such as a deployment server or an indexer cluster master node.

Question 6

The universal forwarder has which capabilities when sending data? (select all that apply)



Question 7

Which optional configuration setting in inputs .conf allows you to selectively forward the data to specific indexer(s)?



Answer : A

https://docs.splunk.com/Documentation/Splunk/7.0.3/Forwarding/Routeandfilterdatad#Perform_selective_indexing_and_forwarding

Specifies a comma-separated list of tcpout group names. Use this setting to selectively forward your data to specific indexers by specifying the tcpout groups that the forwarder should use when forwarding the data. Define the tcpout group names in the outputs.conf file in [tcpout:<tcpout_group_name>] stanzas. The groups present in defaultGroup in [tcpout] stanza in the outputs.conf file.


Page:    1 / 14   
Total 196 questions