Question 1
Which Splunk indexer operating system platform is supported when sending logs from a Windows universal forwarder?
Question 2
An add-on has configured field aliases for source IP address and destination IP address fields. A specific user prefers not to have those fields present in their user context. Based on the default props.conf below, which SPLUNK_HOME/etc/users/buttercup/myTA/local/props.conf stanza can be added to the user's local context to disable the field aliases?

Question 3
Which of the following statements describes how distributed search works?
Question 4
Which of the following statements describe deployment management? (select all that apply)
Question 5
When enabling data integrity control, where does Splunk Enterprise store the hash files for each bucket?
