6/90 questions · Unlock full access
Q1

In which phase of the Splunk Enterprise data pipeline are indexed extraction configurations processed?

Q2

The guidance Splunk gives for estimating size on for syslog data is 50% of original data size. How does this divide between files in the index?

Q3Multiple answers

To improve Splunk performance, parallellngestionPipelines setting can be adjusted on which of the following components in the Splunk architecture? (Select all that apply.)

Q4Multiple answers

Consider a use case involving firewall data. There is no Splunk-supported Technical Add-On, but the vendor has built one. What are the items that must be evaluated before installing the add-on? (Select all that apply.)

Q5

When Splunk is installed, where are the internal indexes stored by default?

Q6

To reduce the captain's work load in a search head cluster, what setting will prevent scheduled searches from running on the captain?