exam questions

Exam SPLK-1003 All Questions

View all questions & answers for the SPLK-1003 exam

Exam SPLK-1003 topic 1 question 4 discussion

Actual exam question from Splunk's SPLK-1003
Question #: 4
Topic #: 1
[All SPLK-1003 Questions]

In which Splunk configuration is the SEDCMD used?

  • A. props.conf
  • B. inputs.conf
  • C. indexes.conf
  • D. transforms.conf
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
emlch
9 months, 1 week ago
There's two transformation methods: SEDCMD or TRANSFORMS SEDCMD: uses props.conf (used to mask or truncate raw data) TRANSFORM: uses props.conf and transforms.conf (transforms matching events based on metadata)
upvoted 3 times
...
alejohu
10 months ago
Selected Answer: A
A is correct
upvoted 2 times
...
Apis
1 year, 5 months ago
Selected Answer: A
A is correct
upvoted 1 times
...
ZeusP
2 years ago
A in props.conf
upvoted 3 times
...
matsumo
2 years ago
A is correct <https://docs.splunk.com/Documentation/Splunk/8.2.0/Data/Anonymizedata> Use the SEDCMD setting. This setting exists in the props.conf configuration file, which you configure on the heavy forwarder.
upvoted 2 times
ucsdmiami2020
1 year, 8 months ago
Agreed A. Quoting the Reference URL "There are two ways to anonymize data with a heavy forwarder: - Use the SEDCMD setting. This setting exists in the props.conf configuration file, which you configure on the heavy forwarder. It acts like a sed *nix script to do replacements and substitutions."
upvoted 1 times
...
...
sargeholik
2 years, 5 months ago
page 182 data admin
upvoted 1 times
...
ames
2 years, 9 months ago
"You can specify a SEDCMD configuration in props.conf to address data that contains characters that the third-party server cannot process. " <https://docs.splunk.com/Documentation/Splunk/8.0.5/Forwarding/Forwarddatatothird-partysystemsd>
upvoted 3 times
ames
2 years, 9 months ago
So yea answer is A.
upvoted 1 times
...
ucsdmiami2020
1 year, 8 months ago
Agreed A. Quoting the Reference URL "By default, Splunk software does not change the content of an event to make its character set compliant with the third-party server. You can specify a SEDCMD configuration in props.conf to address data that contains characters that the third-part server can't process."
upvoted 1 times
...
...
Asami
2 years, 11 months ago
answer is A
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...