Which optional configuration setting in inputs .conf allows you to selectively forward the data to specific indexer(s)?
What happens when the same username exists in Splunk as well as through LDAP?
User role inheritance allows what to be inherited from the parent role? (select all that apply)
When configuring HTTP Event Collector (HEC) input, how would one ensure the events have been indexed?