Exam SPLK-1003 Topic 11 Question 162 Discussion

Actual exam question for Splunk's SPLK-1003 exam
Question #: 162
Topic #: 11
In case of a conflict between a whitelist and a blacklist input setting, which one is used?

Suggested Answer: A Vote an answer

https://docs.splunk.com/Documentation/Splunk/8.0.4/Data/Whitelistorblacklistspecificincomingdata
"It is not necessary to define both an allow list and a deny list in a configuration stanza. The settings are independent. If you do define both filters and a file matches them both, Splunk Enterprise does not index that file, as the blacklist filter overrides the whitelist filter." Source:https://docs.splunk.com/Documentation/Splunk
/8.1.0/Data/Whitelistorblacklistspecificincomingdata

by Samantha at Feb 22, 2026, 03:29 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10