exam questions

Exam SPLK-1003 All Questions

View all questions & answers for the SPLK-1003 exam

Exam SPLK-1003 topic 1 question 61 discussion

Actual exam question from Splunk's SPLK-1003
Question #: 61
Topic #: 1
[All SPLK-1003 Questions]

Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)

  • A. props.conf
  • B. inputs.conf
  • C. rawdata.conf
  • D. transforms.conf
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
roblaw
Highly Voted 3 years, 8 months ago
A & D, From Data Admin pdf, use transformations with props.conf and transforms.conf to: – Mask or delete raw data as it is being indexed –Override sourcetype or host based upon event values – Route events to specific indexes based on event content – Prevent unwanted events from being indexed
upvoted 24 times
...
MonicaKarim
Most Recent 5 days, 7 hours ago
Selected Answer: A
A&D Choose all that apply
upvoted 1 times
...
Frank_Rai
3 months, 2 weeks ago
A & D. The configuration files used to transform raw data ingested by Splunk are: A. props.conf: This file is used to specify how Splunk formats incoming data, including settings for line breaking, timestamp recognition, character set encoding, and field extraction rules. It works in conjunction with transforms.conf for more advanced data transformation tasks. D. transforms.conf: This file is used in conjunction with props.conf to define advanced data transformations, such as field extractions, data masking, and data filtering. It allows for the specification of regular expressions and other settings to extract, transform, and manipulate data. While inputs.conf (B) is indeed a crucial configuration file in Splunk, it's used for specifying the input data settings, such as the type of input, the path for data ingestion, and various parameters for data collection, rather than transforming the data. rawdata.conf (C) is not a standard configuration file in Splunk.
upvoted 1 times
...
PKUSER
5 months, 4 weeks ago
A (props.conf) is more about parsing and interpreting data, while D (transforms.conf) is focused on transforming raw data before indexing So probably D
upvoted 1 times
...
k_alex
7 months ago
with SEDCMD, props.conf is ok but using transformation command, props.conf and transforms.conf will be required.
upvoted 1 times
...
bobixaka
8 months, 2 weeks ago
Selected Answer: D
Combination of props.conf and transforms.conf is the answer. Some transformations could be done only within props.conf, but since transforms.conf is in the possible answers, it is also a true answer.
upvoted 1 times
...
raizen11
1 year, 3 months ago
ABD for transformation of raw all the three files needed
upvoted 1 times
kirtak
1 year, 2 months ago
inputs.conf is not relevant in the parsing phase
upvoted 1 times
...
...
Apis
2 years, 6 months ago
Selected Answer: A
A & D are correct
upvoted 2 times
...
hwangho
3 years, 6 months ago
Answer: AD https://docs.splunk.com/Documentation/Splunk/8.1.1/Knowledge/Configureadvancedextractionswithfieldtransforms
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago