Splunk Enterprise Certified Admin — Question 60
Log files related to Splunk REST calls can be found in which indexes? (Select all that apply.)
Answer options
- A. _audit
- B. _internal
- C. _thefishbucket
- D. _blocksignature
Correct answer: A, B
Explanation
The correct answers are _audit and _internal because these indexes store logs related to user activities and internal Splunk operations, including REST calls. The _thefishbucket and _blocksignature indexes are not relevant for REST call logs, as they serve different purposes within Splunk.