Question 121
When configuring monitor inputs with whitelists or blacklists, what is the supported method of filtering the lists?
Question 122
Using SEDCMD in props.conf allows raw data to be modified. With the given event below, which option will mask the first three digits of the AcctID field resulting output: [22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309 Event:
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
Question 123
Which of the following apply to how distributed search works? (Select all that apply.)
Question 124
Which layers are involved in Splunk configuration file layering? (select all that apply)
Question 125
The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require multiple indexers. Following best practices, which types of Splunk component instances are needed?