Question 71

This file has been manually created on a universal forwarder

A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new

Which file is now monitored?
  • Question 72

    When configuring HTTP Event Collector (HEC) input, how would one ensure the events have been indexed?
  • Question 73

    Which of the following types of data count against the license daily quota?
  • Question 74

    This file has been manually created on a universal forwarder:
    /opt/splunkforwarder/etc/apps/my_TA/local/inputs.conf
    [monitor:///var/log/messages]
    sourcetype=syslog
    index=syslog
    A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new inputs.conffile:
    /opt/splunk/etc/deployment-apps/my_TA/local/inputs.conf
    [monitor:///var/log/maillog]
    sourcetype=maillog
    index=syslog
    Which file is now monitored?
    /var/log/messages
  • Question 75

    Which option accurately describes the purpose of the HTTP Event Collector (HEC)?