In case of a conflict between a whitelist and a blacklist input setting, which one is used?
When running a real-time search, search results are pulled from which Splunk component?
When deploying apps, which attribute in the forwarder management interface determines the apps that clients install?
Which of the following are methods for adding inputs in Splunk? (Choose all that apply.)
Which option on the Add Data menu is most useful for testing data ingestion without creating inputs.conf?