Practice SPLK-1003 Configuration Files questions with full explanations on every answer.
Start practicing
Configuration Files — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
What is the purpose of the 'disabled=1' attribute in an inputs.conf stanza?
2You have two identical stanzas in different configuration files with the same precedence. How does Splunk determine which one wins?
3You have defined a setting in $SPLUNK_HOME/etc/system/local/inputs.conf and the same setting exists in $SPLUNK_HOME/etc/apps/my_app/local/inputs.conf. Which value takes precedence?
4Which configuration file is used to define index-time field extractions and line-breaking rules?
5You need to modify the default behavior of a Splunk application without editing the files inside the 'default' directory. Where should you create the override file?
6If a setting is defined in both $SPLUNK_HOME/etc/system/local/props.conf and $SPLUNK_HOME/etc/apps/my_app/default/props.conf, which one wins?
7You need to perform a regex-based routing operation to send data to different indexes based on the host. Which file must be configured to define the routing regex?
8A user reports that a setting in props.conf is not being applied. You want to see the final merged configuration for a specific sourcetype on a specific host. Which tool should you use?
9Where is the global configuration for Splunk Enterprise stored?
10Which file would you edit to change the TCP listening port for a Splunk Universal Forwarder?
11How does Splunk handle configuration files that are missing a required attribute?
12What is the effect of setting 'TRANSFORMS-routing' in props.conf?
13You are troubleshooting a parsing issue. You want to see the configuration file path that contributed a specific setting. What flag should you use with btool?
14If a user creates a configuration in their 'user' directory, how does it compare in precedence to the 'app' directory?
15You need to ensure that specific data is sent to a specific indexer using the outputs.conf file. Which stanza is used for this?
16When using transforms.conf to extract fields, what is the 'SOURCE_KEY' setting used for?
17Which file is responsible for defining how data is rotated in an index?
18Which stanza is required in props.conf to identify a sourcetype?
19In props.conf, what does the 'REPORT-' prefix signify?
20What happens if you have a syntax error in a .conf file?
21What is the purpose of the 'TIME_PREFIX' attribute in props.conf?
22If you want to debug why a specific sourcetype is not applying, which btool command helps identify the configuration file responsible?
23When using btool, what does the output show by default?
24Which command is used to restart the Splunk service after modifying configuration files?
25Which TWO of the following are valid ways to define field extractions?
26Which THREE of the following are true regarding the behavior of 'btool'?
27Which TWO directories are part of the standard Splunk configuration file precedence hierarchy?
28Which THREE configuration files are most critical for defining how data is ingested and parsed?
29Which TWO of the following are true about 'local' versus 'default' directories?
30Which TWO attributes in props.conf are commonly used to handle multiline events?
31Which THREE of the following are true regarding the configuration precedence of apps?
32Which TWO of the following are valid stanza types found in indexes.conf?
33Which THREE of the following represent true statements about the 'transforms.conf' file?
34Which TWO of the following locations are valid for placing a custom 'inputs.conf' file?
The Configuration Files domain covers the key concepts tested in this area of the SPLK-1003 exam blueprint published by Splunk. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all SPLK-1003 domains — no account required.
The Courseiva SPLK-1003 question bank contains 34 questions in the Configuration Files domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Configuration Files domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included