What happens to the indexer cluster when the indexer Cluster Master (CM) runs out of disk space?
Answer : C
A customer is using regex to whitelist access logs and secure logs from a web server, but only the access logs are being ingested. Which troubleshooting resource would provide insight into why the secure logs are not being ingested?
Answer : B
As a best practice which of the following should be used to ingest data on clustered indexers?
Answer : B
How does Monitoring Console (MC) initially identify the server role(s) of a new Splunk Instance?
Answer : C
Which of the following statements is true, as it pertains to search head clustering (SHC)?
Answer : B
A customer is having issues with truncated events greater than 64K. What configuration should be deployed to a universal forwarder (UF) to fix the issue?
Answer : C
When using SAML, where does user authentication occur?
Answer : A