nerdexam
Splunk

SPLK-3003 · Question #19

Consider the scenario where the /var/log directory contains the files secure, messages, cron, audit. A customer has created the following inputs.conf stanzas in the same Splunk app in order to…

The correct answer is A. /var/log/secure. https://community.splunk.com/t5/Archive/Multiple-stanza-in-inputs-conf-for-the-same-folder/m-

Data Ingestion and Configuration

Question

Consider the scenario where the /var/log directory contains the files secure, messages, cron, audit. A customer has created the following inputs.conf stanzas in the same Splunk app in order to attempt to monitor the files secure and messages:

Which file(s) will actually be actively monitored?

Options

  • A/var/log/secure
  • B/var/log/messages
  • C/var/log/messages, /var/log/cron, /var/log/audit, /var/log/secure
  • D/var/log/secure, /var/log/messages

How the community answered

(44 responses)
  • A
    77% (34)
  • B
    2% (1)
  • C
    7% (3)
  • D
    14% (6)

Explanation

https://community.splunk.com/t5/Archive/Multiple-stanza-in-inputs-conf-for-the-same-folder/m-

Topics

#inputs.conf#file monitoring#stanza precedence#monitor input

Community Discussion

No community discussion yet for this question.

Full SPLK-3003 Practice