Which of the following are available input methods when adding a file input in Splunk Web? (Choose all that apply.)
Which of the following are available input methods when adding a file input in Splunk Web? (Choose all that apply.)
When adding a file input in Splunk Web, you have the options to 'Index once,' which means the file is indexed one time and not monitored for further changes, and 'Continuously monitor,' which means the file is continuously monitored for updates. These methods allow flexibility depending on whether the data in the file is static or dynamic.
The correct answers are A & D
Agreed A and D. Quoting the Splunk Reference URL https://docs.splunk.com/Documentation/Splunk/8.2.2/Data/Howdoyouwanttoadddata The fastest way to add data to your Splunk Cloud instance or Splunk Enterprise deployment is to use Splunk Web. After you access the Add Data page, choose one of three options for getting data into your Splunk platform deployment with Splunk Web: (1) Upload, (2) Monitor, (3) Forward The Upload option lets you upload a file or archive of files for indexing. When you choose Upload option, Splunk Web opens the upload process page. Monitor. For Splunk Enterprise installations, the Monitor option lets you monitor one or more files, directories, network streams, scripts, Event Logs (on Windows hosts only), performance metrics, or any other type of machine data that the Splunk Enterprise instance has access to.
I don't see an option to turn on monitor once. Spluk continuasly monitor the file for updates.
ans is AD
A &D are correct
A and D
A & D would be the answers
AD is correct
Answer would be D
There is no option to monitor once, as splunk will continusly check for update so A is not valid
But there is an option to index once and that is what the option is so would be A&D