Labour Day Sale Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 713PS592

SPLK-2001 Splunk Certified Developer Exam Questions and Answers

Questions 4

Log files related to Splunk REST calls can be found in which indexes? (Select all that apply.)

Options:

A.

_audit

B.

_internal

C.

_thefishbucket

D.

_blocksignature

Buy Now
Questions 5

Which of the following options would be the best way to identify processor bottlenecks of a search?

Options:

A.

Using the REST API.

B.

Using the search job inspector.

C.

Using the Splunk Monitoring Console.

D.

Searching the Splunk logs using index=“internal”.

Buy Now
Questions 6

Suppose the following query in a Simple XML dashboard returns a table including hyperlinks:

index news sourcetype web_proxy | table sourcetype title link

Which of the following is a valid dynamic drilldown element to allow a user of the dashboard to visit the hyperlinks contained in the link field?

Options:

A.

B.

$$row.link$$

C.

$row.link|n$

D.

http://localhost:8000/debug/refresh

Buy Now
Questions 7

Which of the following are reserved field names in a KV Store? (Select all that apply.)

Options:

A.

_key

B.

_time

C.

_user

D.

_source

Buy Now
Questions 8

When added to an app’s default.meta file, which of the following makes one of its views available to other apps?

Options:

A.

export = app

B.

export = none

C.

export = view

D.

export = system

Buy Now
Questions 9

Which of the following are benefits from using Simple XML Extensions? (Select all that apply.)

Options:

A.

Add custom layouts.

B.

Add custom graphics.

C.

Add custom behaviors.

D.

Limit Splunk license consumption based on host.

Buy Now
Questions 10

Which statements are true regarding HEC (HTTP Event Collector) tokens? (Select all that apply.)

Options:

A.

Multiple tokens can be created for use with different sourcetypes and indexes.

B.

The edit token http admin role capability is required to create a token.

C.

To create a token, send a POST request to services/collector endpoint.

D.

Tokens can be edited using the data/inputs/http/{tokenName} endpoint.

Buy Now
Questions 11

Which of the following formats are valid for a Splunk REST URI?

Options:

A.

host:port/endpoint

B.

scheme://host/servicesNS/*/

C.

$SPLUNK HOME/services/endpoint

D.

scheme://host:port/services/endpoint

Buy Now
Questions 12

When output_mode is not used, which element of a feed is a human readable name for a returned entry?

Options:

A.

Author

B.

Title

C.

Link

D.

Id

Buy Now
Questions 13

Which files within an app contain permissions information? (Select all that apply.)

Options:

A.

local/metadata.conf

B.

metadata/local.meta

C.

default/metadata.conf

D.

metadata/default.meta

Buy Now
Questions 14

Which Splunk REST endpoint is used to create a KV store collection?

Options:

A.

/storage/collections

B.

/storage/kvstore/create

C.

/storage/collections/config

D.

/storage/kvstore/collections

Buy Now
Questions 15

Using Splunk Web to modify config settings for a shared object, a revised config file with those changes is placed in which directory?

Options:

A.

$SPLUNK_HOME/etc/apps/myApp/local

B.

$SPLUNK_HOME/etc/system/default/

C.

$SPLUNK_HOME/etc/system/local

D.

$SPLUNK_HOME/etc/apps/myApp/default

Buy Now
Questions 16

When using the Splunk REST API, which of the following containers is/are included in the Atom Feed response? (Select all that apply.)

Options:

A.

B.

C.

D.

Buy Now
Questions 17

A fellow Splunk administrator is reviewing an app that has been downloaded from splunkbase and deployed in an organization. The admin has e-mailed the following configuration snippet with a brief note that says “fix the permissions”.

In what configuration file should the snippet be placed?

[]

access = read : [ * ], write : [ admin ] export - system

(Assume that $APP_HOME refers to the path that the app is installed, e.g. $SPLUNK_HOME/etc/apps/)

Options:

A.

$APP_HOME/default/app.conf

B.

$APP_HOME/local/default.meta

C.

$APP_HOME/metadata/local.meta

D.

$SPLUNK_HOME/etc/system/local/server.conf

Buy Now
Questions 18

When updating a knowledge object via REST, which of the following are valid values for the sharing Access Control List property?

Options:

A.

App

B.

User

C.

Global

D.

Nobody

Buy Now
Questions 19

In a DELETE request, what would omitting the value of _key from the REST endpoint do?

Options:

A.

Clean the KV store, deleting all content.

B.

Produce the syntax error “Key value missing”.

C.

Cause all records in a collection to be deleted.

D.

Mean that the _key value must be passed as an argument.

Buy Now
Questions 20

Which HTTP Event Collector (HEC) endpoint should be used to collect data in the following format?

{“message”:“Hello World”, “foo”:“bar”, “pony”:“buttercup”}

Options:

A.

data/inputs/http/{name}

B.

services/collector/raw

C.

services/collector

D.

data/inputs/http

Buy Now
Questions 21

A KV store collection can be associated with a namespace for which of the following users?

Options:

A.

Nobody

B.

Users in the admin role.

C.

Users in the admin and power roles.

D.

Users in the admin, power, and splunk-system-user roles.

Buy Now
Exam Code: SPLK-2001
Exam Name: Splunk Certified Developer Exam
Last Update: Apr 22, 2024
Questions: 70

PDF + Testing Engine

$66.4  $165.99

Testing Engine

$46  $114.99
buy now SPLK-2001 testing engine

PDF (Q&A)

$42  $104.99
buy now SPLK-2001 pdf