Which search will show all deployment client messages from the client (UF)?
A.
index=_audit component=DC* host= | stats count by message
B.
index=_audit component=DC* host= | stats count by message
C.
index=_internal component= DC* host= | stats count by message
D.
index=_internal component=DS* host= | stats count by message
The Answer Is:
C
This question includes an explanation.
Explanation:
The index=_internal component=DC* host= search will show all deployment client messages from the universal forwarder. The component field indicates the type of Splunk component that generated the message, and the host field indicates the host name of the machine that sent the message. The index=_audit component=DC* host= search will not return any results, because the deployment client messages are not stored in the _audit index. The index=_internal component=DS* host= search will show the deployment server messages from the deployment server, not the client. The index=_audit component=DS* host= search will also not return any results, for the same reason as above
SPLK-2002 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"