Exam SPLK-3003 All QuestionsBrowse all questions from this exam
Question 32

The data in Splunk is now subject to auditing and compliance controls. A customer would like to ensure that at least one year of logs are retained for both

Windows and Firewall events. What data retention controls must be configured?

    Correct Answer: A

    To ensure that at least one year of logs are retained for Windows and Firewall events in Splunk, the data retention controls that must be configured are 'maxTotalDataSizeMB' and 'frozenTimePeriodInSecs'. The 'maxTotalDataSizeMB' parameter limits the total size of data that can be stored, while the 'frozenTimePeriodInSecs' parameter defines the time for which the data is retained before it is frozen. Together, these settings manage both the size and time-based retention policies necessary for complying with auditing and compliance controls.

Discussion
huu_nguyenOption: A

A is the one

pepeperezOption: A

I would say A, Splunk volume is nothing specific

RedYetiOption: D

'e' is missing in "maxTotalDataSizMB"

spl_bonnOption: A

A is correct.

RedtonyeahOption: A

A, the rest of configuration doesnt have sense