Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkEnterprise Certified Admin

Domain 3Objective 1

Inputs Overview SPLK-1003 Practice Questions (Page 4)

Part of the Getting Data In domain, which makes up ~17% of our current practice bank. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~4–7 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
7concepts

Questions 16–20

  1. 16application · medium

    A Splunk admin is configuring a new input for firewall logs. The logs have a timestamp format that Splunk does not recognize by default. The admin has created a custom sourcetype called 'firewall_logs' in inputs.conf. What should the admin do next to ensure the timestamp is parsed correctly?

    Select an answer first
  2. 17application · medium

    A Splunk admin is setting up an input to monitor a directory where multiple applications write log files. Each application writes to a different subdirectory, and the admin wants to ensure that events from each application are tagged with the correct host. The logs are in a standard format that Splunk recognizes. What should the admin configure in the input stanza?

    Select an answer first
  3. 18expert · hard

    A Splunk admin is ingesting logs from a custom application that writes events in a format where multiple lines form a single event. The default line-breaking is splitting these events incorrectly. The admin has created a custom sourcetype and needs to configure the parsing to treat the multi-line events as single events. What should the admin configure in props.conf?

    Select an answer first
  4. 19application · medium

    A Splunk admin needs to ingest data from a network device that sends logs via syslog. The device does not support any other protocol. The admin wants to ensure that the logs are received and tagged with the device's hostname. What should the admin configure?

    Select an answer first
  5. 20foundation · easy

    Which Splunk input option is used to collect data from a TCP or UDP port?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1003” is a trademark of its owner, used for identification only.