nerdexam
Splunk

SPLK-1003 · Question #53

Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)

The correct answer is A. props.conf D. transforms.conf. Splunk uses props.conf and transforms.conf together to define and apply data transformation rules during ingestion.

Splunk Indexing

Question

Which configuration files are used to transform raw data ingested by Splunk? (Choose all that apply.)

Options

  • Aprops.conf
  • Binputs.conf
  • Crawdata.conf
  • Dtransforms.conf

How the community answered

(35 responses)
  • A
    89% (31)
  • B
    3% (1)
  • C
    9% (3)

Why each option

Splunk uses props.conf and transforms.conf together to define and apply data transformation rules during ingestion.

Aprops.confCorrect

props.conf defines source type properties and references transform stanzas via TRANSFORMS- settings, triggering field extractions and other processing rules.

Binputs.conf

inputs.conf defines data collection sources and input methods, not how raw data is parsed or transformed.

Crawdata.conf

rawdata.conf is not a valid Splunk configuration file and does not exist in the Splunk configuration framework.

Dtransforms.confCorrect

transforms.conf contains the actual transformation logic - including regex-based field extractions, data masking rules, and lookup definitions - that props.conf stanzas invoke.

Concept tested: Splunk data transformation configuration files

Source: https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf

Topics

#data transformation#configuration files#props.conf#transforms.conf

Community Discussion

No community discussion yet for this question.

Full SPLK-1003 Practice