| Exam Name: | Splunk Enterprise Certified Admin | ||
| Exam Code: | SPLK-1003 Dumps | ||
| Vendor: | Splunk | Certification: | Splunk Enterprise Certified Admin |
| Questions: | 211 Q&A's | Shared By: | alyssia |
Which of the following is the recommended guideline for creating a new user role?
The following stanza is active in indexes.conf:
[cat_facts]
maxHotSpanSecs = 3600
frozenTimePeriodInSecs = 2630000
maxTota1DataSizeMB = 650000
All other related indexes.conf settings are default values.
If the event timestamp was 3739283 seconds ago, will it be searchable?
A user recently installed an application to index NCINX access logs. After configuring the application, they realize that no data is being ingested. Which configuration file do they need to edit to ingest the access logs to ensure it remains unaffected after upgrade?