Question 51

An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data is
300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the index?
  • Question 52

    What are the values for host and index for [stanza1] used by Splunk during index time, given the following configuration files?
  • Question 53

    In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?

    Event example:
  • Question 54

    Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as follows: 123-44-5678.
    Which configuration file and stanza pair will mask possible SSNs in the log events?
  • Question 55

    Which Splunk component does a search head primarily communicate with?