exam questions

Exam SPLK-1003 All Questions

View all questions & answers for the SPLK-1003 exam

Exam SPLK-1003 topic 1 question 93 discussion

Actual exam question from Splunk's SPLK-1003
Question #: 93
Topic #: 1
[All SPLK-1003 Questions]

In which phase do indexed extractions in props.conf occur?

  • A. Inputs phase
  • B. Parsing phase
  • C. Indexing phase
  • D. Searching phase
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
babusartop17
Highly Voted 3 years, 11 months ago
B is correct. The following items in the phases below are listed in the order Splunk applies them (ie LINE_BREAKER occurs before TRUNCATE). Input phase inputs.conf props.conf CHARSET NO_BINARY_CHECK CHECK_METHOD CHECK_FOR_HEADER (deprecated) PREFIX_SOURCETYPE sourcetype wmi.conf regmon-filters.conf Structured parsing phase props.conf INDEXED_EXTRACTIONS, and all other structured data header extractions Parsing phase props.conf LINE_BREAKER, TRUNCATE, SHOULD_LINEMERGE, BREAK_ONLY_BEFORE_DATE, and all other line merging settings TIME_PREFIX, TIME_FORMAT, DATETIME_CONFIG (datetime.xml), TZ, and all other time extraction settings and rules TRANSFORMS which includes per-event queue filtering, per-event index assignment, per-event routing SEDCMD MORE_THAN, LESS_THAN transforms.conf stanzas referenced by a TRANSFORMS clause in props.conf LOOKAHEAD, DEST_KEY, WRITE_META, DEFAULT_VALUE, REPEAT_MATCH
upvoted 13 times
sesanchez88
3 years, 10 months ago
You're right. Structured parsing phase: --------------------------------------------- props.conf INDEXED_EXTRACTIONS, and all other structured data header extractions URL: https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/Configurationparametersandthedatapipeline
upvoted 6 times
...
...
AnupamaManjunath
Highly Voted 4 years ago
A. Input phase Data admin PDF - page 242
upvoted 10 times
...
Atch0071
Most Recent 6 months ago
• Indexed extractions are input phase props.conf settings – In this scenario, the settings belong on forwarder – Check props.conf.spec for more options Datadmin page: 341 Correct Ans: A
upvoted 2 times
ProfessorJayy
4 months, 1 week ago
where are people referencing this pdf from?
upvoted 1 times
RoPsur
1 month, 3 weeks ago
The instructor led course in Splunk training, costs thousands of dollars.
upvoted 1 times
...
...
...
HNaka
11 months ago
Selected Answer: B
My answer is B.
upvoted 1 times
...
adamsca
1 year, 5 months ago
Selected Answer: B
B is correct in my opinion.
upvoted 2 times
...
erick165
1 year, 9 months ago
Selected Answer: B
" Structured parsing phase props.conf INDEXED_EXTRACTIONS, and all other structured data header extractions "
upvoted 1 times
...
tmmt
1 year, 10 months ago
Selected Answer: B
B, index extractions (INDEX_EXTRATIONS) is done in parsing phase https://docs.splunk.com/Documentation/Splunk/9.0.4/Admin/Configurationparametersandthedatapipeline Structured parsing phase props.conf INDEXED_EXTRACTIONS, and all other structured data header extractions
upvoted 2 times
...
anonyuser
2 years ago
docs hint at A Data Admin 9.0 pdf page 341 "Indexed extractions are input phase props.conf settings"
upvoted 3 times
...
Mando22
2 years, 3 months ago
Correct Answer: B
upvoted 1 times
...
Steve2610
2 years, 5 months ago
Selected Answer: A
Data Admin Slide 262
upvoted 1 times
...
denominator
2 years, 6 months ago
Selected Answer: A
Pg 262 data admin pdf
upvoted 1 times
...
Ailen_Man
2 years, 7 months ago
Answer is B, Structured parsing phase props.conf INDEXED_EXTRACTIONS, and all other structured data header extractions
upvoted 1 times
...
tomod1
2 years, 7 months ago
Selected Answer: A
A is correct "Structured Data Header Extraction and configuration # These special string delimiters, which are single ASCII characters, # can be used in the settings that follow, which state # "You can use the delimiters for structured data header extraction with # this setting. INDEXED_EXTRACTIONS = <CSV|TSV|PSV|W3C|JSON|HEC> * The type of file that Splunk software should expect for a given source type, and the extraction and/or parsing method that should be used on the file." https://docs.splunk.com/Documentation/Splunk/8.2.6/Admin/Propsconf
upvoted 1 times
tomod1
2 years, 7 months ago
* This setting applies at input time, when data is first read by Splunk software, such as on a forwarder that has configured inputs acquiring the data.
upvoted 1 times
...
...
BlueRoselia
2 years, 10 months ago
Answer A&B Generally, fields should be extracted at search time, however there are certain use cases when index time field extractions can be used Provision the extraction during the input or parsing phase –On the forwarder for structured inputs –On the indexer for fields that may be negatively impacting search performance uses three configuration files props.conf, transforms.conf on the indexer and fields.conf on the search head If I have to give one answer, I choose parsing the indexers can handle the extra load better.
upvoted 1 times
...
FishingZodiac
3 years ago
Selected Answer: A
Data admin p263
upvoted 6 times
...
loky0
3 years, 4 months ago
P263 in Data Admin pdf says "Indexed Extractions are input phase props.conf settings". So it'd be A. But detailed documentations break down the steps, "INDEXED_EXTRACTIONS, and all other structured data header extractions" are part of the Structured Parsing Phase. So it might be B as well..... https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/Configurationparametersandthedatapipeline
upvoted 4 times
...
AngusBlack
3 years, 6 months ago
It's A. From https://docs.splunk.com/Documentation/Splunk/8.1.1/Admin/Propsconf Heading: Structured Data Header Extraction and configuration "This setting applies at input time, when data is first read by Splunk software, such as on a forwarder that has configured inputs acquiring the data." INDEXED_EXTRACTIONS = <CSV|TSV|PSV|W3C|JSON|HEC>
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago