Splunk Enterprise Certified Architect — Question 69
How can internal logging levels in a Splunk environment be changed to troubleshoot an issue? (Choose all that apply.)
Answer options
- A. Edit log-local.cfg.
- B. Use the Monitoring Console (MC).
- C. Use Splunk Web.
- D. Use Splunk command line.
Correct answer: A, C, D
Explanation
The correct options for changing logging levels are A, C, and D. Editing log-local.cfg allows for direct configuration changes, while Splunk Web provides a user interface for modifications. Using the command line also permits adjustments; however, option B, using the Monitoring Console, is not typically used for changing logging levels.