Splunk SPLK-1005 - Splunk Cloud Certified Admin Exam

Question #11 (Topic: Exam A)
A monitor has been created in inputs.conf for a directory that contains a mix of file types.
How would a Cloud Admin fine-tune assigned sourcetypes for different files in the directory during the input phase?
A. On the Indexer parsing the data, leave sourcetype as automatic for the directory monitor. Then create a props.conf that assigns a specific sourcetype by source stanza. B. On the forwarder collecting the data, leave sourcetype as automatic for the directory monitor. Then create a props.conf that assigns a specific sourcetype by source stanza. C. On the Indexer parsing the data, set multiple sourcetype_source attributes for the directory monitor collecting the files. Then create a props.conf that filters out unwanted files. D. On the forwarder collecting the data, set multiple sourcetype_source attributes for the directory monitor collecting the files. Then create a props.conf that filters out unwanted files.
Answer: B
Question #12 (Topic: Exam A)
Windows input types are collected in Splunk via a script which is configurable using the GUI. What is this type of input called?
A. Batch B. Scripted C. Modular D. Front-end
Answer: C
Question #13 (Topic: Exam A)
Which file or folder below is not a required part of a deployment app?
A. app.conf (in default or local) B. local.meta C. metadata folder D. props.conf
Answer: C
Question #14 (Topic: Exam A)
Which of the following files is used for both search-time and index-time configuration?
A. inputs.conf B. props.conf C. macros.conf D. savedsearch.conf
Answer: B
Question #15 (Topic: Exam A)
What Splunk command will allow an administrator to view the runtime configuration instructions for a monitored file in inputs.conf on the forwarders?
A. ./splunk _internal call /services/data/inputs/filemonitor B. ./splunk show config inputs.conf C. ./splunk _internal rest /services/data/inputs/monitor D. ./splunk show config inputs
Answer: C
Download Exam
Page: 3 / 12
Total 60 questions