Question 36

Consider the scenario where the /var/logdirectory contains the files secure, messages, cron, audit.
A customer has created the following inputs.confstanzas in the same Splunk app in order to attempt to monitor the files secure and messages:

Which file(s) will actually be actively monitored?
/var/log/secure
  • Question 37

    Which configuration item should be set to false to significantly improve data ingestion performance?
  • Question 38

    What is required to setup the HTTP Event Collector (HEC)?
  • Question 39

    Which statement is true about subsearches?
  • Question 40

    What should be considered when running the following CLI commands with a goal of accelerating an index cluster migration to new hardware?