exam questions

Exam SPLK-1003 All Questions

View all questions & answers for the SPLK-1003 exam

Exam SPLK-1003 topic 1 question 74 discussion

Actual exam question from Splunk's SPLK-1003
Question #: 74
Topic #: 1
[All SPLK-1003 Questions]

Which configuration file would be used to forward the Splunk internal logs from a search head to the indexer?

  • A. props.conf
  • B. inputs.conf
  • C. outputs.conf
  • D. collections.conf
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
hwangho
Highly Voted 3 years, 7 months ago
C is correct. https://docs.splunk.com/Documentation/Splunk/8.1.1/DistSearch/Forwardsearchheaddata
upvoted 9 times
ucsdmiami2020
2 years, 11 months ago
Per the provided Splunk reference URL by @hwangho, scroll to section Forward search head data, subsection titled, 2. Configure the search head as a forwarder. "Create an outputs.conf file on the search head that configures the search head for load-balanced forwarding across the set of search peers (indexers)."
upvoted 1 times
...
...
FrozenYeti
Most Recent 4 weeks, 1 day ago
Selected Answer: C
The correct answer is C. This question is assuming that the indexer is already configured for listening, you are only configuring the search head to forward data to the indexer, in which case you only need to modify the outputs.conf on the search head.
upvoted 1 times
...
PrincePazol
6 months, 3 weeks ago
Selected Answer: C
In outputs.conf: [tcpout] defaultGroup = indexers1 [indexAndForward] index=false [tcpout:indexers1] server = 10.1.1.197:9997, 10.1.1.200:9997
upvoted 1 times
...
CactiAZ
9 months, 1 week ago
Selected Answer: C
This community usually gets these questions right, but I'm surprised by how many are putting the wrong answer. The correct answer is C. See the link in hwangho's post. Search heads, and all Splunk instances, already have inputs built to read internal logs by default. They just need an outputs.conf to create a tcpout stanza to your indexers to get them to send their internal logs, which is what this question is asking about. In our Splunk environment we have NEVER set up an inputs for internal logs, we only deploy an outputs.conf with our indexers listed in a tcpout stanza, and we get all of our internal logs just fine. If you had other logs on a search head (like from a script or something), then yes, you would need an inputs.conf to get those to be read. But that is definitely not what this question is asking about.
upvoted 2 times
...
yaman778
1 year ago
Selected Answer: B
B for sure. inputs.conf allows you to define data inputs that the Splunk instance should monitor and forward to indexers. Use monitor stanza specifying the path to log files and destination indexer’s host name, port. Stanza Sample [monitor:///opt/splunk/var/log/splunk] Index = _internal Soucetype = Splunkd Disabled = false _TCP_ROUTING = indexer_group
upvoted 1 times
...
kolaturka
1 year, 4 months ago
he correct answer is B. inputs.conf is used to configure the inputs on a Splunk instance, including forwarding data from one instance to another. In this case, to forward the Splunk internal logs from a search head to the indexer, you would need to add a stanza to inputs.conf on the search head that specifies the indexer as the destination for the logs. The props.conf file is used to configure how data is processed after it has been indexed, outputs.conf is used to configure the destination of data for specific stanzas, and collections.conf is used for managing data in collections.
upvoted 1 times
...
anonyuser
1 year, 8 months ago
Just for a little clarification, configuring the sh as a forwarder using outputs.conf does not necessarily tell the sh to send a certain type of data that you would use inputs.conf for. However, this is talking about _internal, which I believe is data that is sent by default, without the need for inputs.conf. Please correct me if I am wrong here
upvoted 1 times
...
Hudda
3 years, 1 month ago
Friends, could you please confirm this answer?
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago