SPLK-1005 Splunk Cloud Certified Admin Questions and Answers
Which of the following tasks is the responsibility of a Splunk Cloud administrator?
A customer wants to mask unstructured data before sending it to Splunk Cloud. Where should SEBCMD be configured for this?
What syntax is required in inputs.conf to ingest data from files or directories?
A user has been asked to mask some sensitive data without tampering with the structure of the file /var/log/purchase/transactions. log that has the following format:

A)

B)

C)

D)

The following sample log event shows evidence of credit card numbers being present in the transactions. loc file.

Which of these SEDCM3 settings will mask this and other suspected credit card numbers with an Y character for each character being masked? The indexed event should be formatted as follows:

A)

B)

C)

D)

What is the correct syntax to monitor /apache/too/logo, /apache/bor/logs, and /apache/bar/l/logo?
A)

B)

C)

D)

Which monitor statement will retrieve only files that start with " access " in the directory /opt/log/ww2/?

Which of the following app installation scenarios can be achieved without involving Splunk Support?
Which of the following is not considered a best practice for the deployment server?
Which configuration shown is used to enable a forwarder as a deployment client of the server 10.1.2.3?
Li was asked to create a Splunk configuration to monitor syslog files stored on Linux servers at their organization. This configuration will be pushed out to multiple systems via a Splunk app using the on-prem deployment server.
The system administrators have provided Li with a directory listing for the logging locations on three syslog hosts, which are representative of the file structure for all systems collecting this data. An example from each system is shown below:

A)

B)

C)

D)

Windows Input types are collected in Splunk via a script which is configurable using the GUI. What is this type of input called?
Files from multiple systems are being stored on a centralized log server. The files are organized into directories based on the original server they came from. Which of the following is a recommended approach for correctly setting the host values based on their origin?
What is the default port for sending data via HTTP Event Collector to Splunk Cloud?
