Question 111
Which of the following is a benefit of distributed search?
Question 112
In case of a conflict between a whitelist and a blacklist input setting, which one is used?
Question 113
For single line event sourcetypes, it is most efficient to set SHOULD_LINEMERGEto what value?
Question 114
Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
Question 115
How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON A)

B)

C)

D)


B)

C)

D)
