A log file contains 193 days worth of timestamped events. Which monitor stanza would be used to collect data 45 days old and newer from that log file?
Which configuration file would be used to forward the Splunk internal logs from a search head to the indexer?
An index stores its data in buckets. Which default directories does Splunk use to store buckets? (Choose all that apply.)