Splunk

SPLK-1003 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 120-question bank.

Provider
Splunk
Question bank
120
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for SPLK-1003, a certification listed under Splunk. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Splunk. The certification credential is issued by Splunk, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which setting in indexes.conf allows data retention to be controlled by time?

    Choose one answer.

    • maxDaysToKeep
    • moveToFrozenAfter
    • maxDataRetentionTime
    • frozenTimePeriodInSecs
  2. Question 2 · 1

    Where should apps be located on the deployment server that the clients pull from?

    Choose one answer.

    • $SPLUNK_HOME/etc/apps
    • $SPLUNK_HOME/etc/search
    • $SPLUNK_HOME/etc/master-apps
    • $SPLUNK_HOME/etc/deployment-apps
  3. Question 3 · 1

    Using SEDCMD in props.conf allows raw data to be modified. With the given event below, which option will mask the first three digits of the AcctID field resulting output: [22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309 Event: [22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309

    Choose one answer.

    • SEDCMD-1acct = s/VendorID=\d{3}(\d{4})/VendorID=xxx/g
    • SEDCMD-xxxAcct = s/AcctID=\d{3}(\d{4})/AcctID=xxx/g
    • SEDCMD-1acct = s/AcctID=\d{3}(\d{4})/AcctID=\1xxx/g
    • SEDCMD-1acct = s/AcctID=\d{3}(\d{4})/AcctID=xxx\1/g
  4. Question 4 · 1

    Which of the following accurately describes HTTP Event Collector indexer acknowledgement?

    Choose one answer.

    • It requires a separate channel provided by the client.
    • It is configured the same as indexer acknowledgement used to protect in-flight data.
    • It can be enabled at the global setting level.
    • It stores status information on the Splunk server.
  5. Question 5 · 1

    What action is required to enable forwarder management in Splunk Web?

    Choose one answer.

    • Navigate to Settings > Server Settings > General Settings, and set an App server port.
    • Navigate to Settings > Forwarding and receiving, and click on Enable Forwarding.
    • Create a server class and map it to a client in SPLUNK_HOME/etc/system/local/serverclass.conf.
    • Place an app in the SPLUNK_HOME/etc/deployment-apps directory of the deployment server.
  6. Question 6 · 1

    Which of the following is accurate regarding the input phase?

    Choose one answer.

    • Breaks data into events with timestamps.
    • Applies event-level transformations.
    • Fine-tunes metadata.
    • Performs character encoding.
  7. Question 7 · 1

    Which of the following monitor inputs stanza headers would match all of the following files? /var/log/www1/secure.log /var/log/www/secure.l /var/log/www/logs/secure.logs /var/log/www2/secure.log

    Choose one answer.

    • [monitor:///var/log/.../secure.*]
    • [monitor:///var/log/www1/secure.*]
    • [monitor:///var/log/www1/secure.log]
    • [monitor:///var/log/www*/secure.*]
  8. Question 8 · 1

    What are the values for host and index for [stanza1] used by Splunk during index time, given the following configuration files?

    Choose one answer.

    Question illustration 1
    • host=server1 index=unixinfo
    • host=server1 index=searchinfo
    • host=searchsvr1 index=searchinfo
    • host=unixsvr1 index=unixinfo
  9. Question 9 · 1

    An index stores its data in buckets. Which default directories does Splunk use to store buckets? (Choose all that apply.)

    Choose all answers that apply.

    • bucketdb
    • frozendb
    • colddb
    • db
  10. Question 10 · 1

    This file has been manually created on a universal forwarder: /opt/splunkforwarder/etc/apps/my_TA/local/inputs.conf [monitor:///var/log/messages] sourcetype=syslog index=syslog A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new inputs.conf file: /opt/splunk/etc/deployment-apps/my_TA/local/inputs.conf [monitor:///var/log/maillog] sourcetype=maillog index=syslog Which file is now monitored?

    Choose one answer.

    • /var/log/messages
    • /var/log/maillog
    • /var/log/maillog and /var/log/messages
    • none of the above
  11. Question 11 · 1

    A log file contains 193 days worth of timestamped events. Which monitor stanza would be used to collect data 45 days old and newer from that log file?

    Choose one answer.

    • followTail = -45d
    • ignore = 45d
    • includeNewerThan = 45d
    • ignoreOlderThan = 45d
  12. Question 12 · 1

    Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?

    Choose one answer.

    • Indexer
    • Deployment server
    • Universal forwarder
    • Search head
  13. Question 13 · 1

    Which Splunk forwarder has a built-in license?

    Choose one answer.

    • Light forwarder
    • Heavy forwarder
    • Universal forwarder
    • Cloud forwarder
  14. Question 14 · 1

    Consider the following stanza in inputs.conf: What will the value of the source filed be for events generated by this scripts input?

    Choose one answer.

    Question illustration 1
    • /opt/splunk/etc/apps/search/bin/lister.sh
    • unknown
    • lister
    • lister.sh
  15. Question 15 · 1

    Which of the following applies only to Splunk index data integrity check?

    Choose one answer.

    • Lookup table
    • Summary Index
    • Raw data in the index
    • Data model acceleration

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free