Exam Name: | Splunk Enterprise Certified Admin | ||
Exam Code: | SPLK-1003 Dumps | ||
Vendor: | Splunk | Certification: | Splunk Enterprise Certified Admin |
Questions: | 185 Q&A's | Shared By: | tomos |
The following stanza is active in indexes.conf:
[cat_facts]
maxHotSpanSecs = 3600
frozenTimePeriodInSecs = 2630000
maxTota1DataSizeMB = 650000
All other related indexes.conf settings are default values.
If the event timestamp was 3739283 seconds ago, will it be searchable?
When using a directory monitor input, specific source type can be selectively overridden using which configuration file?
Which of the following are available input methods when adding a file input in Splunk Web? (Choose all that
apply.)
After configuring a universal forwarder to communicate with an indexer, which index can be checked via the Splunk Web UI for a successful connection?