Exam Name: | Splunk Enterprise Certified Admin | ||
Exam Code: | SPLK-1003 Dumps | ||
Vendor: | Splunk | Certification: | Splunk Enterprise Certified Admin |
Questions: | 189 Q&A's | Shared By: | roy |
The following stanza is active in indexes.conf:
[cat_facts]
maxHotSpanSecs = 3600
frozenTimePeriodInSecs = 2630000
maxTota1DataSizeMB = 650000
All other related indexes.conf settings are default values.
If the event timestamp was 3739283 seconds ago, will it be searchable?
When configuring monitor inputs with whitelists or blacklists, what is the supported method of filtering the lists?
Which of the following accurately describes HTTP Event Collector indexer acknowledgement?
Which of the following are methods for adding inputs in Splunk? (select all that apply)