Question 1

Which setting in inputs.conf can be used to set the host field to a static value for a monitor input?
  • Question 2

    Where does the regex replacement processor run?
  • Question 3

    What is the main difference between events indexes and metrics indexes in Splunk Cloud?
  • Question 4

    Which attribute in outputs.conf can be used to specify the load balancing method for a group of forwarders?
  • Question 5

    Which of the following methods is valid for creating index-time field extractions?