exam questions

Exam SPLK-2002 All Questions

View all questions & answers for the SPLK-2002 exam

Exam SPLK-2002 topic 1 question 68 discussion

Actual exam question from Splunk's SPLK-2002
Question #: 68
Topic #: 1
[All SPLK-2002 Questions]

Which of the following statements about integrating with third-party systems is true? (Select all that apply.)

  • A. A Hadoop application can search data in Splunk.
  • B. Splunk can search data in the Hadoop File System (HDFS).
  • C. You can use Splunk alerts to provision actions on a third-party system.
  • D. You can forward data from Splunk forwarder to a third-party system without indexing it first.
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
M_K_S
Highly Voted 3 years, 3 months ago
My Answer is BCD
upvoted 11 times
...
qtygbapjpesdayazko
Most Recent 8 months, 3 weeks ago
Selected Answer: BC
B. Splunk can search data in the Hadoop File System (HDFS). C. You can use Splunk alerts to provision actions on a third-party system. D. You can forward data from Splunk forwarder to a third-party system without indexing it first.
upvoted 1 times
...
Proctor
1 year, 4 months ago
Selected Answer: AC
Unpopular answer I guess, but I'd say A and C. A. Hadoop applications can search data in Splunk using the REST API at minimum C. Alert actions can be used to trigger actions based on a query result But not... B. Splunk can't search data on HDFS without indexing it first. D. I see other comments saying that there's a 3rd party tool that can receive data directly from a UF, but assume that this is talking about first-party architecture as designed (and, besides, they have a lawsuit open against Cribl :))
upvoted 3 times
Bob_Hob
1 week, 6 days ago
Update - both cribl and splunk won the lawsuit! xD
upvoted 1 times
...
qtygbapjpesdayazko
6 months, 1 week ago
The D is correct, you can use de UF and HF to send data do other systems: https://www.tekstream.com/blog/route-data-to-multiple-destinations/
upvoted 2 times
...
...
brettw
1 year, 5 months ago
Selected Answer: BC
100% B,C,D B. Splunk can search data in the Hadoop File System (HDFS). - Correct C. You can use Splunk alerts to provision actions on a third-party system. - Correct: Systems such as Critical Start can utilize alerts to provision additional actions from within their system. D. You can forward data from Splunk forwarder to a third-party system without indexing it first. - Correct: As mentioned Cribl LogStream can ingest data directly from the UF modify the streamed data, and then forward that data to the indexer(s)
upvoted 3 times
...
dseitz
2 years, 4 months ago
B,C Not D bc the it can only send data AFTER it's indexed
upvoted 1 times
RedYeti
1 year, 10 months ago
LogStream from Cribl can receive data from Forwarders
upvoted 1 times
...
[Removed]
1 year, 11 months ago
You are incorrect: https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd
upvoted 2 times
...
diddely
2 years, 1 month ago
That would defy the whole purpose of the HF.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago