A & D, From Data Admin pdf, use transformations with props.conf and transforms.conf to:
– Mask or delete raw data as it is being indexed
–Override sourcetype or host based upon event values
– Route events to specific indexes based on event content
– Prevent unwanted events from being indexed
A & D.
The configuration files used to transform raw data ingested by Splunk are:
A. props.conf: This file is used to specify how Splunk formats incoming data, including settings for line breaking, timestamp recognition, character set encoding, and field extraction rules. It works in conjunction with transforms.conf for more advanced data transformation tasks.
D. transforms.conf: This file is used in conjunction with props.conf to define advanced data transformations, such as field extractions, data masking, and data filtering. It allows for the specification of regular expressions and other settings to extract, transform, and manipulate data.
While inputs.conf (B) is indeed a crucial configuration file in Splunk, it's used for specifying the input data settings, such as the type of input, the path for data ingestion, and various parameters for data collection, rather than transforming the data.
rawdata.conf (C) is not a standard configuration file in Splunk.
A (props.conf) is more about parsing and interpreting data, while D (transforms.conf) is focused on transforming raw data before indexing
So probably D
Combination of props.conf and transforms.conf is the answer.
Some transformations could be done only within props.conf, but since transforms.conf is in the possible answers, it is also a true answer.
Answer: AD
https://docs.splunk.com/Documentation/Splunk/8.1.1/Knowledge/Configureadvancedextractionswithfieldtransforms
upvoted 4 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
roblaw
Highly Voted 3Â years, 8Â months agoMonicaKarim
Most Recent 5Â days, 7Â hours agoFrank_Rai
3Â months, 2Â weeks agoPKUSER
5Â months, 4Â weeks agok_alex
7Â months agobobixaka
8Â months, 2Â weeks agoraizen11
1Â year, 3Â months agokirtak
1Â year, 2Â months agoApis
2Â years, 6Â months agohwangho
3Â years, 6Â months ago