A customer with a large distributed environment has blacklisted a large lookup from the search bundle to decrease the bundle size using distsearch.conf. After this change, when running searches utilizing the lookup that was blacklisted they see error messages in the Splunk Search UI stating the lookup file does not exist.
What can the customer do to resolve the issue?
A [script://] input sends data to a Splunk forwarder using which method?
A customer has asked for a five-node search head cluster (SHC), but does not have the storage budget to use a replication factor greater than 2. They would like to understand what might happen in terms of the users' ability to view historic scheduled search results if they log onto a search head which doesn't contain one of the
2 copies of a given search artifact.
Which of the following statements best describes what would happen in this scenario?
In which of the following scenarios should base configurations be used to provide consistent, repeatable, and supportable configurations?
A [script://]input sends data to a Splunk forwarder using which method?