In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?
Event example:
How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON A)
B)
C)
D)
In which Splunk configuration is the SEDCMDused?
What are the values for host and index for [stanza1] used by Splunk during index time, given the following configuration files?
Which Splunk component performs indexing and responds to search requests from the search head?