Exam Name: | Splunk Enterprise Certified Admin Exam | ||
Exam Code: | SPLK-1003 Dumps | ||
Vendor: | Splunk | Certification: | Splunk Enterprise Certified Admin |
Questions: | 174 Q&A's | Shared By: | maximillian |
Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
A non-clustered Splunk environment has three indexers (A,B,C) and two search heads (X, Y). During a search executed on search head X, indexer A crashes. What is Splunk's response?
The Splunk administrator wants to ensure data is distributed evenly amongst the indexers. To do this, he runs
the following search over the last 24 hours:
index=*
What field can the administrator check to see the data distribution?