Question 1

Which of the following must be done to define user permissions when integrating Splunk with LDAP?
  • Question 2

    How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON A)

    B)

    C)

    D)
  • Question 3

    In which phase do indexed extractions in props.conf occur?
  • Question 4

    In a distributed environment, which Splunk component is used to distribute apps and configurations to the other Splunk instances?
  • Question 5

    The universal forwarder has which capabilities when sending data? (select all that apply)