Where are Splunk Data Model Acceleration (DMA) summaries stored?
In a large cloud customer environment with many (>100) dynamically created endpoint systems, each with a UF already deployed, what is the best approach for associating these systems with an appropriate serverclass on the deployment server?
A site from a multi-site indexer cluster needs to be decommissioned. Which of the following actions must be taken?
Which event processing pipeline contains the regex replacement processor that would be called upon to run event masking routines on events as they are ingested?