Consider the search shown below.

What is this search's intended function?
The data in Splunk is now subject to auditing and compliance controls. A customer would like to ensure that at least one year of logs are retained for both Windows and Firewall events. What data retention controls must be configured?
Data can be onboarded using apps, Splunk Web, or the CLI.
Which is the PS preferred method?
When a bucket rolls from cold to frozen on a clustered indexer, which of the following scenarios occurs?
A working search head cluster has been set up and used for 6 months with just the native/local Splunk user authentication method. In order to integrate the search heads with an external Active Directory server using LDAP, which of the following statements represents the most appropriate method to deploy the configuration to the servers?