SPLK-2002 Exam QuestionsBrowse all questions from this exam

SPLK-2002 Exam - Question 68


Which of the following statements about integrating with third-party systems is true? (Select all that apply.)

Show Answer
Correct Answer: AC

A Hadoop application can search data in Splunk using the REST API, enabling integration between the two platforms. Additionally, Splunk alerts can be configured to trigger actions on third-party systems based on query results, allowing automated responses to specific conditions detected in Splunk's data. These capabilities highlight the flexibility and integration potential of Splunk with other systems.

Discussion

5 comments
Sign in to comment
M_K_SOptions: BCD
Nov 5, 2020

My Answer is BCD

ProctorOptions: AC
Oct 21, 2022

Unpopular answer I guess, but I'd say A and C. A. Hadoop applications can search data in Splunk using the REST API at minimum C. Alert actions can be used to trigger actions based on a query result But not... B. Splunk can't search data on HDFS without indexing it first. D. I see other comments saying that there's a 3rd party tool that can receive data directly from a UF, but assume that this is talking about first-party architecture as designed (and, besides, they have a lawsuit open against Cribl :))

qtygbapjpesdayazko
Aug 18, 2023

The D is correct, you can use de UF and HF to send data do other systems: https://www.tekstream.com/blog/route-data-to-multiple-destinations/

brettwOptions: BC
Sep 16, 2022

100% B,C,D B. Splunk can search data in the Hadoop File System (HDFS). - Correct C. You can use Splunk alerts to provision actions on a third-party system. - Correct: Systems such as Critical Start can utilize alerts to provision additional actions from within their system. D. You can forward data from Splunk forwarder to a third-party system without indexing it first. - Correct: As mentioned Cribl LogStream can ingest data directly from the UF modify the streamed data, and then forward that data to the indexer(s)

dseitzOptions: BC
Oct 10, 2021

B,C Not D bc the it can only send data AFTER it's indexed

diddely
Dec 28, 2021

That would defy the whole purpose of the HF.

[Removed]
Feb 28, 2022

You are incorrect: https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd

RedYeti
Apr 25, 2022

LogStream from Cribl can receive data from Forwarders

qtygbapjpesdayazkoOptions: BC
Jun 7, 2023

B. Splunk can search data in the Hadoop File System (HDFS). C. You can use Splunk alerts to provision actions on a third-party system. D. You can forward data from Splunk forwarder to a third-party system without indexing it first.