New Year Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

SPLK-2002 Questions and Answers

Question # 6

Which Splunk cluster feature requires additional indexer storage?

A.

Search Head Clustering

B.

Indexer Discovery

C.

Indexer Acknowledgement

D.

Index Summarization

Full Access
Question # 7

Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)

A.

Install Enterprise Security on the deployer.

B.

Install Enterprise Security on a staging instance.

C.

Copy the Enterprise Security configurations to the deployer.

D.

Use the deployer to deploy Enterprise Security to the cluster members.

Full Access
Question # 8

Splunk Enterprise platform instrumentation refers to data that the Splunk Enterprise deployment logs in the _introspection index. Which of the following logs are included in this index? (Select all that apply.)

A.

audit.log

B.

metrics.log

C.

disk_objects.log

D.

resource_usage.log

Full Access
Question # 9

When designing the number and size of indexes, which of the following considerations should be applied?

A.

Expected daily ingest volume, access controls, number of concurrent users

B.

Number of installed apps, expected daily ingest volume, data retention time policies

C.

Data retention time policies, number of installed apps, access controls

D.

Expected daily ingest volumes, data retention time policies, access controls

Full Access
Question # 10

Which of the following Splunk deployments has the recommended minimum components for a high-availability search head cluster?

A.

2 search heads, 1 deployer, 2 indexers

B.

3 search heads, 1 deployer, 3 indexers

C.

1 search head, 1 deployer, 3 indexers

D.

2 search heads, 1 deployer, 3 indexers

Full Access
Question # 11

(How can a Splunk admin control the logging level for a specific search to get further debug information?)

A.

Configure infocsv_log_level = DEBUG in limits.conf.

B.

Insert | noop log_debug=* after the base search.

C.

Open the Search Job Inspector in Splunk Web and modify the log level.

D.

Use Settings > Server settings > Server logging in Splunk Web.

Full Access
Question # 12

(If the maxDataSize attribute is set to auto_high_volume in indexes.conf on a 64-bit operating system, what is the maximum hot bucket size?)

A.

4 GB

B.

750 MB

C.

10 GB

D.

1 GB

Full Access
Question # 13

Which server.conf attribute should be added to the master node's server.conf file when decommissioning a site in an indexer cluster?

A.

site_mappings

B.

available_sites

C.

site_search_factor

D.

site_replication_factor

Full Access
Question # 14

Which of the following strongly impacts storage sizing requirements for Enterprise Security?

A.

The number of scheduled (correlation) searches.

B.

The number of Splunk users configured.

C.

The number of source types used in the environment.

D.

The number of Data Models accelerated.

Full Access
Question # 15

Which of the following is true regarding Splunk Enterprise's performance? (Select all that apply.)

A.

Adding search peers increases the maximum size of search results.

B.

Adding RAM to existing search heads provides additional search capacity.

C.

Adding search peers increases the search throughput as the search load increases.

D.

Adding search heads provides additional CPU cores to run more concurrent searches.

Full Access
Question # 16

(A new Splunk Enterprise deployment is being architected, and the customer wants to ensure that the data to be indexed is encrypted. Where should TLS be turned on in the Splunk deployment?)

A.

Deployment server to deployment clients.

B.

Splunk forwarders to indexers.

C.

Indexer cluster peer nodes.

D.

Browser to Splunk Web.

Full Access
Question # 17

What is the default log size for Splunk internal logs?

A.

10MB

B.

20 MB

C.

25MB

D.

30MB

Full Access
Question # 18

In the deployment planning process, when should a person identify who gets to see network data?

A.

Deployment schedule

B.

Topology diagramming

C.

Data source inventory

D.

Data policy definition

Full Access
Question # 19

As a best practice, where should the internal licensing logs be stored?

A.

Indexing layer.

B.

License server.

C.

Deployment layer.

D.

Search head layer.

Full Access
Question # 20

(A customer wishes to keep costs to a minimum, while still implementing Search Head Clustering (SHC). What are the minimum supported architecture standards?)

A.

Three Search Heads and One SHC Deployer

B.

Two Search Heads with the SHC Deployer being hosted on one of the Search Heads

C.

Three Search Heads but using a Deployment Server instead of a SHC Deployer

D.

Two Search Heads, with the SHC Deployer being on the Deployment Server

Full Access
Question # 21

A customer has a four site indexer cluster. The customer has requirements to store five copies of searchable data, with one searchable copy of data at the origin site, and one searchable copy at the disaster recovery site (site4).

Which configuration meets these requirements?

A.

site_replication_factor = origin:2, site4:l, total:3

B.

site_replication_factor = origin:l, site4:l, total:5

C.

site_search_factor = origin:2, site4:l, total:3

D.

site search factor = origin:1, site4:l, total:5

Full Access
Question # 22

Which of the following describe migration from single-site to multisite index replication?

A.

A master node is required at each site.

B.

Multisite policies apply to new data only.

C.

Single-site buckets instantly receive the multisite policies.

D.

Multisite total values should not exceed any single-site factors.

Full Access
Question # 23

Which of the following tasks should the architect perform when building a deployment plan? (Select all that apply.)

A.

Use case checklist.

B.

Install Splunk apps.

C.

Inventory data sources.

D.

Review network topology.

Full Access
Question # 24

(Which of the following has no impact on search performance?)

A.

Decreasing the phone home interval for deployment clients.

B.

Increasing the number of indexers in the indexer tier.

C.

Allocating compute and memory resources with Workload Management.

D.

Increasing the number of search heads in a Search Head Cluster.

Full Access
Question # 25

Which of the following options in limits, conf may provide performance benefits at the forwarding tier?

A.

Enable the indexed_realtime_use_by_default attribute.

B.

Increase the maxKBps attribute.

C.

Increase the parallellngestionPipelines attribute.

D.

Increase the max_searches per_cpu attribute.

Full Access
Question # 26

Which of the following artifacts are included in a Splunk diag file? (Select all that apply.)

A.

OS settings.

B.

Internal logs.

C.

Customer data.

D.

Configuration files.

Full Access
Question # 27

(Which of the following is a benefit of using SmartStore?)

A.

Automatic selection of replication and search factors.

B.

Separating storage from compute.

C.

Knowledge Object replication.

D.

Cluster Manager is no longer required.

Full Access
Question # 28

(Where can files be placed in a configuration bundle on a search peer that will persist after a new configuration bundle has been deployed?)

A.

In the $SPLUNK_HOME/etc/slave-apps//local folder.

B.

In the $SPLUNK_HOME/etc/master-apps//local folder.

C.

Nowhere; the entire configuration bundle is overwritten with each push.

D.

In the $SPLUNK_HOME/etc/slave-apps/_cluster/local folder.

Full Access
Question # 29

(The performance of a specific search is performing poorly. The search must run over All Time and is expected to have very few results. Analysis shows that the search accesses a very large number of buckets in a large index. What step would most significantly improve the performance of this search?)

A.

Increase the disk I/O hardware performance.

B.

Increase the number of indexing pipelines.

C.

Set indexed_realtime_use_by_default = true in limits.conf.

D.

Change this to a real-time search using an All Time window.

Full Access
Question # 30

Stakeholders have identified high availability for searchable data as their top priority. Which of the following best addresses this requirement?

A.

Increasing the search factor in the cluster.

B.

Increasing the replication factor in the cluster.

C.

Increasing the number of search heads in the cluster.

D.

Increasing the number of CPUs on the indexers in the cluster.

Full Access
Question # 31

Which of the following is unsupported in a production environment?

A.

Cluster Manager can run on the Monitoring Console instance in smaller environments.

B.

Search Head Cluster Deployer can run on the Monitoring Console instance in smaller environments.

C.

Search heads in a Search Head Cluster can run on virtual machines.

D.

Indexers in an indexer cluster can run on virtual machines.

Full Access
Question # 32

Which of the following configuration attributes must be set in server, conf on the cluster manager in a single-site indexer cluster?

A.

master_uri

B.

site

C.

replication_factor

D.

site_replication_factor

Full Access
Question # 33

What is the minimum reference server specification for a Splunk indexer?

A.

12 CPU cores, 12GB RAM, 800 IOPS

B.

16 CPU cores, 16GB RAM, 800 IOPS

C.

24 CPU cores, 16GB RAM, 1200 IOPS

D.

28 CPU cores, 32GB RAM, 1200 IOPS

Full Access
Question # 34

Splunk Enterprise performs a cyclic redundancy check (CRC) against the first and last bytes to prevent the same file from being re-indexed if it is rotated or renamed. What is the number of bytes sampled by default?

A.

128

B.

512

C.

256

D.

64

Full Access
Question # 35

How does the average run time of all searches relate to the available CPU cores on the indexers?

A.

Average run time is independent of the number of CPU cores on the indexers.

B.

Average run time decreases as the number of CPU cores on the indexers decreases.

C.

Average run time increases as the number of CPU cores on the indexers decreases.

D.

Average run time increases as the number of CPU cores on the indexers increases.

Full Access
Question # 36

Where in the Job Inspector can details be found to help determine where performance is affected?

A.

Search Job Properties > runDuration

B.

Search Job Properties > runtime

C.

Job Details Dashboard > Total Events Matched

D.

Execution Costs > Components

Full Access
Question # 37

A Splunk instance has crashed, but no crash log was generated. There is an attempt to determine what user activity caused the crash by running the following search:

What does searching for closed_txn=0 do in this search?

A.

Filters results to situations where Splunk was started and stopped multiple times.

B.

Filters results to situations where Splunk was started and stopped once.

C.

Filters results to situations where Splunk was stopped and then immediately restarted.

D.

Filters results to situations where Splunk was started, but not stopped.

Full Access
Question # 38

Several critical searches that were functioning correctly yesterday are not finding a lookup table today. Which log file would be the best place to start troubleshooting?

A.

btool.log

B.

web_access.log

C.

health.log

D.

configuration_change.log

Full Access
Question # 39

(A high-volume source and a low-volume source feed into the same index. Which of the following items best describe the impact of this design choice?)

A.

Low volume data will improve the compression factor of the high volume data.

B.

Search speed on low volume data will be slower than necessary.

C.

Low volume data may move out of the index based on volume rather than age.

D.

High volume data is optimized by the presence of low volume data.

Full Access
Question # 40

When planning a search head cluster, which of the following is true?

A.

All search heads must use the same operating system.

B.

All search heads must be members of the cluster (no standalone search heads).

C.

The search head captain must be assigned to the largest search head in the cluster.

D.

All indexers must belong to the underlying indexer cluster (no standalone indexers).

Full Access
Question # 41

Which Splunk internal field can confirm duplicate event issues from failed file monitoring?

A.

_time

B.

_indextime

C.

_index_latest

D.

latest

Full Access
Question # 42

(What is a recommended way to improve search performance?)

A.

Use the shortest query possible.

B.

Filter as much as possible in the initial search.

C.

Use non-streaming commands as early as possible.

D.

Leverage the not expression to limit returned results.

Full Access
Question # 43

On search head cluster members, where in $splunk_home does the Splunk Deployer deploy app content by default?

A.

etc/apps/

B.

etc/slave-apps/

C.

etc/shcluster/

D.

etc/deploy-apps/

Full Access
Question # 44

An indexer cluster is being designed with the following characteristics:

• 10 search peers

• Replication Factor (RF): 4

• Search Factor (SF): 3

• No SmartStore usage

How many search peers can fail before data becomes unsearchable?

A.

Zero peers can fail.

B.

One peer can fail.

C.

Three peers can fail.

D.

Four peers can fail.

Full Access
Question # 45

Which of the following clarification steps should be taken if apps are not appearing on a deployment client? (Select all that apply.)

A.

Check serverclass.conf of the deployment server.

B.

Check deploymentclient.conf of the deployment client.

C.

Check the content of SPLUNK_HOME/etc/apps of the deployment server.

D.

Search for relevant events in splunkd.log of the deployment server.

Full Access
Question # 46

(On which Splunk components does the Splunk App for Enterprise Security place the most load?)

A.

Indexers

B.

Cluster Managers

C.

Search Heads

D.

Heavy Forwarders

Full Access
Question # 47

When should a dedicated deployment server be used?

A.

When there are more than 50 search peers.

B.

When there are more than 50 apps to deploy to deployment clients.

C.

When there are more than 50 deployment clients.

D.

When there are more than 50 server classes.

Full Access
Question # 48

A search head has successfully joined a single site indexer cluster. Which command is used to configure the same search head to join another indexer cluster?

A.

splunk add cluster-config

B.

splunk add cluster-master

C.

splunk edit cluster-config

D.

splunk edit cluster-master

Full Access
Question # 49

A customer has a Search Head Cluster (SHC) with site1 and site2. Site1 has five search heads and Site2 has four. Site1 search heads are preferred captains. What action should be taken on Site2 in a network failure between the sites?

A.

Disable elections and set a static captain, then restart the cluster.

B.

No action is required.

C.

Set a dynamic captain manually and restart.

D.

Disable elections and set a static captain, notifying all members.

Full Access
Question # 50

What is needed to ensure that high-velocity sources will not have forwarding delays to the indexers?

A.

Increase the default value of sessionTimeout in server, conf.

B.

Increase the default limit for maxKBps in limits.conf.

C.

Decrease the value of forceTimebasedAutoLB in outputs. conf.

D.

Decrease the default value of phoneHomelntervallnSecs in deploymentclient .conf.

Full Access
Question # 51

A Splunk architect has inherited the Splunk deployment at Buttercup Games and end users are complaining that the events are inconsistently formatted for a web source. Further investigation reveals that not all weblogs flow through the same infrastructure: some of the data goes through heavy forwarders and some of the forwarders are managed by another department.

Which of the following items might be the cause of this issue?

A.

The search head may have different configurations than the indexers.

B.

The data inputs are not properly configured across all the forwarders.

C.

The indexers may have different configurations than the heavy forwarders.

D.

The forwarders managed by the other department are an older version than the rest.

Full Access
Question # 52

Which of the following items are important sizing parameters when architecting a Splunk environment? (select all that apply)

A.

Number of concurrent users.

B.

Volume of incoming data.

C.

Existence of premium apps.

D.

Number of indexes.

Full Access
Question # 53

(What is the best way to configure and manage receiving ports for clustered indexers?)

A.

Use Splunk Web to create the receiving port on each peer node.

B.

Define the receiving port in /etc/deployment-apps/cluster-app/local/inputs.conf and deploy it to the peer nodes.

C.

Run the splunk enable listen command on each peer node.

D.

Define the receiving port in /etc/manager-apps/_cluster/local/inputs.conf and push it to the peer nodes.

Full Access
Question # 54

Which tool(s) can be leveraged to diagnose connection problems between an indexer and forwarder? (Select all that apply.)

A.

telnet

B.

tcpdump

C.

splunk btool

D.

splunk btprobe

Full Access
Question # 55

Which of the following commands is used to clear the KV store?

A.

splunk clean kvstore

B.

splunk clear kvstore

C.

splunk delete kvstore

D.

splunk reinitialize kvstore

Full Access
Question # 56

What is the expected minimum amount of storage required for data across an indexer cluster with the following input and parameters?

• Raw data = 15 GB per day

• Index files = 35 GB per day

• Replication Factor (RF) = 2

• Search Factor (SF) = 2

A.

85 GB per day

B.

50 GB per day

C.

100 GB per day

D.

65 GB per day

Full Access
Question # 57

(When planning user management for a new Splunk deployment, which task can be disregarded?)

A.

Identify users authenticating with Splunk native authentication.

B.

Identify users authenticating with Splunk using LDAP or SAML.

C.

Determine the number of users present in Splunk log events.

D.

Determine the capabilities users need within the Splunk environment.

Full Access
Question # 58

Following Splunk recommendations, where could the Monitoring Console (MC) be installed in a distributed deployment with an indexer cluster, a search head cluster, and 1000 forwarders?

A.

On a search peer in the cluster.

B.

On the deployment server.

C.

On the search head cluster deployer.

D.

On a search head in the cluster.

Full Access
Question # 59

A customer has a multisite cluster with site1 and site2 configured. They want to configure search heads in these sites to get search results only from data stored on their local sites. Which step prevents this behavior?

A.

Set site=site0 in the [general] stanza of server.conf on the search head.

B.

Configure site_search_factor = site1:1, total:2.

C.

Implement only two indexers per site.

D.

Configure site_search_factor = site1:2, total:3.

Full Access
Question # 60

Which of the following statements about integrating with third-party systems is true? (Select all that apply.)

A.

A Hadoop application can search data in Splunk.

B.

Splunk can search data in the Hadoop File System (HDFS).

C.

You can use Splunk alerts to provision actions on a third-party system.

D.

You can forward data from Splunk forwarder to a third-party system without indexing it first.

Full Access