Q: 1
A customer has a network device that transmits logs directly with UDP or TCP over SSL. Using PS best
practices, which ingestion method should be used?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
A customer with a large distributed environment has blacklisted a large lookup from the search
bundle to decrease the bundle size using distsearch.conf. After this change, when running searches
utilizing the lookup that was blacklisted they see error messages in the Splunk Search UI stating the
lookup file does not exist.
What can the customer do to resolve the issue?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
In the diagrammed environment shown below, the customer would like the data read by the
universal forwarders to set an indexed field containing the UF’s host name. Where would the parsing
configurations need to be installed for this to work?


Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
A customer has 30 indexers in an indexer cluster configuration and two search heads. They are
working on writing SPL search for a particular use-case, but are concerned that it takes too long to
run for short time durations.
How can the Search Job Inspector capabilities be used to help validate and understand the customer
concerns?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
Which of the following is the most efficient search?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
A customer has a number of inefficient regex replacement transforms being applied. When under
heavy load the indexers are struggling to maintain the expected indexing rate. In a worst case
scenario, which queue(s) would be expected to fill up?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
Where does the bloomfilter reside?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
A customer has written the following search:
How can the search be rewritten to maximize efficiency?

How can the search be rewritten to maximize efficiency?

Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
In a single indexer cluster, where should the Monitoring Console (MC) be installed?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
A customer has a multisite cluster (two sites, each site in its own data center) and users experiencing
a slow response when searches are run on search heads located in either site. The Search Job
Inspector shows the delay is being caused by search heads on either site waiting for results to be
returned by indexers on the opposing site. The network team has confirmed that there is limited
bandwidth available between the two data centers, which are in different geographic locations.
Which of the following would be the least expensive and easiest way to improve search
performance?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20 · Page 1 / 2