Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Splunk Exam SPLK-1005 Topic 12 Question 11 Discussion

Actual exam question for Splunk's SPLK-1005 exam
Question #: 11
Topic #: 12
[All SPLK-1005 Questions]

Given the following set of files, which of the monitor stanzas below will result in Splunk monitoring all of the files ending with .log?

Files:

/var/log/www1/secure.log

/var/log/www1/access.log

/var/log/www2/logs/secure.log

/var/log/www2/access.log

/var/log/www2/access.log.1

Show Suggested Answer Hide Answer
Suggested Answer: B

The ellipsis (...) in [monitor:///var/log/.../*.log] allows Splunk to monitor files ending in .log in all nested directories under /var/log/. [Reference: Splunk Docs on monitor stanza syntax]


Contribute your Thoughts:

Daniel
3 days ago
I think Option A is the way to go. The '/*/*.log' pattern will match all the .log files in the immediate subdirectories of /var/log.
upvoted 0 times
...
Charlie
6 days ago
I'm not sure about B. Doesn't the '...' wildcard match any number of directories? Wouldn't that potentially include more files than just the ones ending in .log?
upvoted 0 times
...
Malinda
8 days ago
But A specifies monitoring all files ending with .log in any subdirectory, while B specifies monitoring all files ending with .log in any depth of subdirectories.
upvoted 0 times
...
Nan
10 days ago
I disagree, I believe the correct answer is B.
upvoted 0 times
...
Malinda
18 days ago
I think the answer is A.
upvoted 0 times
...
Lelia
23 days ago
Option B seems the most straightforward way to capture all the .log files across the different directories.
upvoted 0 times
Tiera
8 days ago
I agree, option B covers all the .log files in different directories.
upvoted 0 times
...
Arlene
9 days ago
I think option B is the correct one.
upvoted 0 times
...
...

Save Cancel