Splunk
SPLK-3003 · Question #19
Consider the scenario where the /var/log directory contains the files secure, messages, cron, audit. A customer has created the following inputs.conf stanzas in the same Splunk app in order to…
The correct answer is A. /var/log/secure. https://community.splunk.com/t5/Archive/Multiple-stanza-in-inputs-conf-for-the-same-folder/m-
Data Ingestion and Configuration
Question
Consider the scenario where the /var/log directory contains the files secure, messages, cron, audit. A customer has created the following inputs.conf stanzas in the same Splunk app in order to attempt to monitor the files secure and messages:
Which file(s) will actually be actively monitored?
Options
- A/var/log/secure
- B/var/log/messages
- C/var/log/messages, /var/log/cron, /var/log/audit, /var/log/secure
- D/var/log/secure, /var/log/messages
How the community answered
(44 responses)- A77% (34)
- B2% (1)
- C7% (3)
- D14% (6)
Explanation
https://community.splunk.com/t5/Archive/Multiple-stanza-in-inputs-conf-for-the-same-folder/m-
Topics
#inputs.conf#file monitoring#stanza precedence#monitor input
Community Discussion
No community discussion yet for this question.