(Which command is used to initially add a search head to a single-site indexer cluster?)
New data has been added to a monitor input file. However, searches only show older data.
Which splunkd. log channel would help troubleshoot this issue?
(A new Splunk Enterprise deployment is being architected, and the customer wants to ensure that the data to be indexed is encrypted. Where should TLS be turned on in the Splunk deployment?)
In which phase of the Splunk Enterprise data pipeline are indexed extraction configurations processed?
A customer has a four site indexer cluster. The customer has requirements to store five copies of searchable data, with one searchable copy of data at the origin site, and one searchable copy at the disaster recovery site (site4).
Which configuration meets these requirements?
In splunkd. log events written to the _internal index, which field identifies the specific log channel?
Before users can use a KV store, an admin must create a collection. Where is a collection is defined?
(If the maxDataSize attribute is set to auto_high_volume in indexes.conf on a 64-bit operating system, what is the maximum hot bucket size?)