Splunk Core Certified Consultant SPLK-3003 Exam Practice Test

Page: 1 / 14
Total 85 questions
Question 1

What happens to the indexer cluster when the indexer Cluster Master (CM) runs out of disk space?



Answer : C


Question 2

A customer is using regex to whitelist access logs and secure logs from a web server, but only the access logs are being ingested. Which troubleshooting resource would provide insight into why the secure logs are not being ingested?



Answer : B


Question 3

As a best practice which of the following should be used to ingest data on clustered indexers?



Answer : B


Question 4

How does Monitoring Console (MC) initially identify the server role(s) of a new Splunk Instance?



Answer : C


Question 5

Which of the following statements is true, as it pertains to search head clustering (SHC)?



Answer : B


Question 6

A customer is having issues with truncated events greater than 64K. What configuration should be deployed to a universal forwarder (UF) to fix the issue?



Answer : C


Question 7

When using SAML, where does user authentication occur?



Answer : A


Page:    1 / 14   
Total 85 questions