Search heads in a company's European offices need to be able to search data in their New York offices. They also need to restrict access to certain indexers. What should be configured to allow this type of action?
What are the minimum required settings when creating a network input in Splunk?
Which setting allows the configuration of Splunk to allow events to span over more than one line?
Which feature in Splunk allows Event Breaking, Timestamp extractions, and any advanced configurations
found in props.conf to be validated all through the UI?
Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?
An add-on has configured field aliases for source IP address and destination IP address fields. A specific user prefers not to have those fields present in their user context. Based on the defaultprops.confbelow, whichSPLUNK_HOME/etc/users/buttercup/myTA/local/props.confstanza can be added to the user’s local context to disable the field aliases?
Which layers are involved in Splunk configuration file layering? (select all that apply)