Question 121

When configuring monitor inputs with whitelists or blacklists, what is the supported method of filtering the lists?
  • Question 122

    Using SEDCMD in props.conf allows raw data to be modified. With the given event below, which option will mask the first three digits of the AcctID field resulting output: [22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309 Event:
    [22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309
  • Question 123

    Which of the following apply to how distributed search works? (Select all that apply.)
  • Question 124

    Which layers are involved in Splunk configuration file layering? (select all that apply)
  • Question 125

    The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require multiple indexers. Following best practices, which types of Splunk component instances are needed?