Question 36
An index stores its data in buckets. Which default directories does Splunk use to store buckets? (Choose all that apply.)
Question 37
Which Splunk component does a search head primarily communicate with?
Question 38
Which of the following accurately describes HTTP Event Collector indexer acknowledgement?
Question 39
Which setting in indexes. conf allows data retention to be controlled by time?
Question 40
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs the following search over the last 24 hours:
index=*
What field can the administrator check to see the data distribution?
index=*
What field can the administrator check to see the data distribution?