| Exam Name: | Splunk Enterprise Certified Admin | ||
| Exam Code: | SPLK-1003 Dumps | ||
| Vendor: | Splunk | Certification: | Splunk Enterprise Certified Admin | 
| Questions: | 202 Q&A's | Shared By: | tomos | 
A Splunk administrator has been tasked with developing a retention strategy to have frequently accessed data sets on SSD storage and to have older, less frequently accessed data on slower NAS storage. They have set a mount point for the NAS. Which parameter do they need to modify to set the path for the older, less frequently accessed data in indexes.conf?
Search heads in a company's European offices need to be able to search data in their New York offices. They also need to restrict access to certain indexers. What should be configured to allow this type of action?
When running a real-time search, search results are pulled from which Splunk component?
What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?