exam questions

Exam SPLK-1003 All Questions

View all questions & answers for the SPLK-1003 exam

Exam SPLK-1003 topic 1 question 169 discussion

Actual exam question from Splunk's SPLK-1003
Question #: 169
Topic #: 1
[All SPLK-1003 Questions]

Windows can prevent a Splunk forwarder from reading open files. If files need to be read while they are being written to, what type of input stanza needs to be created?

  • A. Upload
  • B. TailReader
  • C. Monitor
  • D. MonitorNoHandle
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
NastyNutsu
1 month, 1 week ago
Selected Answer: D
Although there are only 3 ways of getting data into Splunk: Upload, Monitor, and Forward. However, MonitorNoHandle is a specific type of Monitor input stanza used for Windows systems to handle open files being written to.
upvoted 1 times
...
RayDogg
1 month, 1 week ago
Selected Answer: D
The correct answer is C. MonitorNoHandle. MonitorNoHandle is a type of input stanza that allows a Splunk forwarder to read files on Windows systems as Windows writes to them. It does this by using a kernel-mode filter driver to capture raw data as it gets written to the file1. This input stanza is useful for files that get locked open for writing, such as the Windows DNS server log file2.
upvoted 1 times
...
RoPsur
3 months, 2 weeks ago
Selected Answer: C
The monitor input is designed to read files, including those that are actively being written to.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago