Question 56
Splunk Enterprise platform instrumentation refers to data that the Splunk Enterprise deployment logs in the
_introspectionindex. Which of the following logs are included in this index? (Select all that apply.)
_introspectionindex. Which of the following logs are included in this index? (Select all that apply.)
Question 57
A Splunk architect has inherited the Splunk deployment at Buttercup Games and end users are complaining that the events are inconsistently formatted for a web sourcetype. Further investigation reveals that not all web logs flow through the same infrastructure: some of the data goes through heavy forwarders and some of the forwarders are managed by another department.
Which of the following items might be the cause for this issue?
Which of the following items might be the cause for this issue?
Question 58
Which of the following is a best practice to maximize indexing performance?
Question 59
A new Splunk customer is using syslog to collect data from their network devices on port 514. What is the best practice for ingesting this data into Splunk?
Question 60
When designing the number and size of indexes, which of the following considerations should be applied?
