Question 51
An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data is
300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the index?
300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the index?
Question 52
What are the values for host and index for [stanza1] used by Splunk during index time, given the following configuration files?


Question 53
In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?

Event example:


Event example:

Question 54
Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as follows: 123-44-5678.
Which configuration file and stanza pair will mask possible SSNs in the log events?
Which configuration file and stanza pair will mask possible SSNs in the log events?
Question 55
Which Splunk component does a search head primarily communicate with?
