Big Cyber Monday Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

SPLK-2002 Questions and Answers

Question # 6

(A new Splunk Enterprise deployment is being architected, and the customer wants to ensure that the data to be indexed is encrypted. Where should TLS be turned on in the Splunk deployment?)

A.

Deployment server to deployment clients.

B.

Splunk forwarders to indexers.

C.

Indexer cluster peer nodes.

D.

Browser to Splunk Web.

Full Access
Question # 7

When troubleshooting a situation where some files within a directory are not being indexed, the ignored files are discovered to have long headers. What is the first thing that should be added to inputs.conf?

A.

Decrease the value of initCrcLength.

B.

Add a crcSalt= attribute.

C.

Increase the value of initCrcLength.

D.

Add a crcSalt= attribute.

Full Access
Question # 8

(What is the expected performance reduction when architecting Splunk in a virtualized environment instead of a physical environment?)

A.

Up to 15%

B.

Between 20% and 45%

C.

0

D.

0.5

Full Access
Question # 9

Which of the following clarification steps should be taken if apps are not appearing on a deployment client? (Select all that apply.)

A.

Check serverclass.conf of the deployment server.

B.

Check deploymentclient.conf of the deployment client.

C.

Check the content of SPLUNK_HOME/etc/apps of the deployment server.

D.

Search for relevant events in splunkd.log of the deployment server.

Full Access
Question # 10

How does the average run time of all searches relate to the available CPU cores on the indexers?

A.

Average run time is independent of the number of CPU cores on the indexers.

B.

Average run time decreases as the number of CPU cores on the indexers decreases.

C.

Average run time increases as the number of CPU cores on the indexers decreases.

D.

Average run time increases as the number of CPU cores on the indexers increases.

Full Access
Question # 11

(An admin removed and re-added search head cluster (SHC) members as part of patching the operating system. When trying to re-add the first member, a script reverted the SHC member to a previous backup, and the member refuses to join the cluster. What is the best approach to fix the member so that it can re-join?)

A.

Review splunkd.log for configuration changes preventing the addition of the member.

B.

Delete the [shclustering] stanza in server.conf and restart Splunk.

C.

Force the member add by running splunk edit shcluster-config —force.

D.

Clean the Raft metadata using splunk clean raft.

Full Access
Question # 12

Following Splunk recommendations, where could the Monitoring Console (MC) be installed in a distributed deployment with an indexer cluster, a search head cluster, and 1000 forwarders?

A.

On a search peer in the cluster.

B.

On the deployment server.

C.

On the search head cluster deployer.

D.

On a search head in the cluster.

Full Access
Question # 13

Which of the following are client filters available in serverclass.conf? (Select all that apply.)

A.

DNS name.

B.

IP address.

C.

Splunk server role.

D.

Platform (machine type).

Full Access
Question # 14

When using the props.conf LINE_BREAKER attribute to delimit multi-line events, the SHOULD_LINEMERGE attribute should be set to what?

A.

Auto

B.

None

C.

True

D.

False

Full Access
Question # 15

When preparing to ingest a new data source, which of the following is optional in the data source assessment?

A.

Data format

B.

Data location

C.

Data volume

D.

Data retention

Full Access
Question # 16

A search head has successfully joined a single site indexer cluster. Which command is used to configure the same search head to join another indexer cluster?

A.

splunk add cluster-config

B.

splunk add cluster-master

C.

splunk edit cluster-config

D.

splunk edit cluster-master

Full Access
Question # 17

A search head cluster member contains the following in its server .conf. What is the Splunk server name of this member?

A.

node1

B.

shc4

C.

idxc2

D.

node3

Full Access
Question # 18

In an indexer cluster, what tasks does the cluster manager perform? (select all that apply)

A.

Generates and maintains the list of primary searchable buckets.

B.

If Indexer Discovery is enabled, provides the list of available peer nodes to forwarders.

C.

Ensures all peer nodes are always using the same version of Splunk.

D.

Distributes app bundles to peer nodes.

Full Access
Question # 19

Which of the following would be the least helpful in troubleshooting contents of Splunk configuration files?

A.

crash logs

B.

search.log

C.

btool output

D.

diagnostic logs

Full Access
Question # 20

Where in the Job Inspector can details be found to help determine where performance is affected?

A.

Search Job Properties > runDuration

B.

Search Job Properties > runtime

C.

Job Details Dashboard > Total Events Matched

D.

Execution Costs > Components

Full Access
Question # 21

A customer plans to ingest 600 GB of data per day into Splunk. They will have six concurrent users, and they also want high data availability and high search performance. The customer is concerned about cost and wants to spend the minimum amount on the hardware for Splunk. How many indexers are recommended for this deployment?

A.

Two indexers not in a cluster, assuming users run many long searches.

B.

Three indexers not in a cluster, assuming a long data retention period.

C.

Two indexers clustered, assuming high availability is the greatest priority.

D.

Two indexers clustered, assuming a high volume of saved/scheduled searches.

Full Access
Question # 22

Which two sections can be expanded using the Search Job Inspector?

A.

Execution costs.

B.

Saved search history.

C.

Search job properties.

D.

Optimization suggestions.

Full Access
Question # 23

On search head cluster members, where in $splunk_home does the Splunk Deployer deploy app content by default?

A.

etc/apps/

B.

etc/slave-apps/

C.

etc/shcluster/

D.

etc/deploy-apps/

Full Access
Question # 24

How can internal logging levels in a Splunk environment be changed to troubleshoot an issue? (select all that apply)

A.

Use the Monitoring Console (MC).

B.

Use Splunk command line.

C.

Use Splunk Web.

D.

Edit log-local. cfg.

Full Access
Question # 25

What does the deployer do in a Search Head Cluster (SHC)? (Select all that apply.)

A.

Distributes apps to SHC members.

B.

Bootstraps a clean Splunk install for a SHC.

C.

Distributes non-search-related and manual configuration file changes.

D.

Distributes runtime knowledge object changes made by users across the SHC.

Full Access
Question # 26

Which Splunk component is mandatory when implementing a search head cluster?

A.

Captain Server

B.

Deployer

C.

Cluster Manager

D.

RAFT Server

Full Access
Question # 27

Which of the following artifacts are included in a Splunk diag file? (Select all that apply.)

A.

OS settings.

B.

Internal logs.

C.

Customer data.

D.

Configuration files.

Full Access
Question # 28

Which Splunk server role regulates the functioning of indexer cluster?

A.

Indexer

B.

Deployer

C.

Master Node

D.

Monitoring Console

Full Access
Question # 29

Which component in the splunkd.log will log information related to bad event breaking?

A.

Audittrail

B.

EventBreaking

C.

IndexingPipeline

D.

AggregatorMiningProcessor

Full Access
Question # 30

In search head clustering, which of the following methods can you use to transfer captaincy to a different member? (Select all that apply.)

A.

Use the Monitoring Console.

B.

Use the Search Head Clustering settings menu from Splunk Web on any member.

C.

Run the splunk transfer shcluster-captain command from the current captain.

D.

Run the splunk transfer shcluster-captain command from the member you would like to become the captain.

Full Access
Question # 31

(Which of the following has no impact on search performance?)

A.

Decreasing the phone home interval for deployment clients.

B.

Increasing the number of indexers in the indexer tier.

C.

Allocating compute and memory resources with Workload Management.

D.

Increasing the number of search heads in a Search Head Cluster.

Full Access
Question # 32

Splunk Enterprise performs a cyclic redundancy check (CRC) against the first and last bytes to prevent the same file from being re-indexed if it is rotated or renamed. What is the number of bytes sampled by default?

A.

128

B.

512

C.

256

D.

64

Full Access
Question # 33

Which index-time props.conf attributes impact indexing performance? (Select all that apply.)

A.

REPORT

B.

LINE_BREAKER

C.

ANNOTATE_PUNCT

D.

SHOULD_LINEMERGE

Full Access
Question # 34

When should a dedicated deployment server be used?

A.

When there are more than 50 search peers.

B.

When there are more than 50 apps to deploy to deployment clients.

C.

When there are more than 50 deployment clients.

D.

When there are more than 50 server classes.

Full Access
Question # 35

When Splunk is installed, where are the internal indexes stored by default?

A.

SPLUNK_HOME/bin

B.

SPLUNK_HOME/var/lib

C.

SPLUNK_HOME/var/run

D.

SPLUNK_HOME/etc/system/default

Full Access
Question # 36

Because Splunk indexing is read/write intensive, it is important to select the appropriate disk storage solution for each deployment. Which of the following statements is accurate about disk storage?

A.

High performance SAN should never be used.

B.

Enable NFS for storing hot and warm buckets.

C.

The recommended RAID setup is RAID 10 (1 + 0).

D.

Virtualized environments are usually preferred over bare metal for Splunk indexers.

Full Access
Question # 37

(What command will decommission a search peer from an indexer cluster?)

A.

splunk disablepeer --enforce-counts

B.

splunk decommission —enforce-counts

C.

splunk offline —enforce-counts

D.

splunk remove cluster-peers —enforce-counts

Full Access
Question # 38

(Where can files be placed in a configuration bundle on a search peer that will persist after a new configuration bundle has been deployed?)

A.

In the $SPLUNK_HOME/etc/slave-apps//local folder.

B.

In the $SPLUNK_HOME/etc/master-apps//local folder.

C.

Nowhere; the entire configuration bundle is overwritten with each push.

D.

In the $SPLUNK_HOME/etc/slave-apps/_cluster/local folder.

Full Access
Question # 39

Which Splunk Enterprise offering has its own license?

A.

Splunk Cloud Forwarder

B.

Splunk Heavy Forwarder

C.

Splunk Universal Forwarder

D.

Splunk Forwarder Management

Full Access
Question # 40

Which of the following is a way to exclude search artifacts when creating a diag?

A.

SPLUNK_HOME/bin/splunk diag --exclude

B.

SPLUNK_HOME/bin/splunk diag --debug --refresh

C.

SPLUNK_HOME/bin/splunk diag --disable=dispatch

D.

SPLUNK_HOME/bin/splunk diag --filter-searchstrings

Full Access
Question # 41

A customer currently has many deployment clients being managed by a single, dedicated deployment server. The customer plans to double the number of clients.

What could be done to minimize performance issues?

A.

Modify deploymentclient. conf to change from a Pull to Push mechanism.

B.

Reduce the number of apps in the Manager Node repository.

C.

Increase the current deployment client phone home interval.

D.

Decrease the current deployment client phone home interval.

Full Access
Question # 42

(What is a recommended way to improve search performance?)

A.

Use the shortest query possible.

B.

Filter as much as possible in the initial search.

C.

Use non-streaming commands as early as possible.

D.

Leverage the not expression to limit returned results.

Full Access
Question # 43

A Splunk environment collecting 10 TB of data per day has 50 indexers and 5 search heads. A single-site indexer cluster will be implemented. Which of the following is a best practice for added data resiliency?

A.

Set the Replication Factor to 49.

B.

Set the Replication Factor based on allowed indexer failure.

C.

Always use the default Replication Factor of 3.

D.

Set the Replication Factor based on allowed search head failure.

Full Access
Question # 44

(What are the possible values for the mode attribute in server.conf for a Splunk server in the [clustering] stanza?)

A.

[clustering] mode = peer

B.

[clustering] mode = searchhead

C.

[clustering] mode = deployer

D.

[clustering] mode = manager

Full Access
Question # 45

Which search will show all deployment client messages from the client (UF)?

A.

index=_audit component=DC* host= | stats count by message

B.

index=_audit component=DC* host= | stats count by message

C.

index=_internal component= DC* host= | stats count by message

D.

index=_internal component=DS* host= | stats count by message

Full Access
Question # 46

Stakeholders have identified high availability for searchable data as their top priority. Which of the following best addresses this requirement?

A.

Increasing the search factor in the cluster.

B.

Increasing the replication factor in the cluster.

C.

Increasing the number of search heads in the cluster.

D.

Increasing the number of CPUs on the indexers in the cluster.

Full Access
Question # 47

Which of the following items are important sizing parameters when architecting a Splunk environment? (select all that apply)

A.

Number of concurrent users.

B.

Volume of incoming data.

C.

Existence of premium apps.

D.

Number of indexes.

Full Access
Question # 48

(Which of the following data sources are used for the Monitoring Console dashboards?)

A.

REST API calls

B.

Splunk btool

C.

Splunk diag

D.

metrics.log

Full Access
Question # 49

To expand the search head cluster by adding a new member, node2, what first step is required?

A.

splunk bootstrap shcluster-config -mgmt_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

B.

splunk init shcluster-config -master_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

C.

splunk init shcluster-config -mgmt_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

D.

splunk add shcluster-member -new_member_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

Full Access
Question # 50

Which command is used for thawing the archive bucket?

A.

Splunk collect

B.

Splunk convert

C.

Splunk rebuild

D.

Splunk dbinspect

Full Access
Question # 51

Which of the following describe migration from single-site to multisite index replication?

A.

A master node is required at each site.

B.

Multisite policies apply to new data only.

C.

Single-site buckets instantly receive the multisite policies.

D.

Multisite total values should not exceed any single-site factors.

Full Access
Question # 52

An index has large text log entries with many unique terms in the raw data. Other than the raw data, which index components will take the most space?

A.

Index files (*. tsidx files).

B.

Bloom filters (bloomfilter files).

C.

Index source metadata (sources.data files).

D.

Index sourcetype metadata (SourceTypes. data files).

Full Access
Question # 53

A new Splunk customer is using syslog to collect data from their network devices on port 514. What is the best practice for ingesting this data into Splunk?

A.

Configure syslog to send the data to multiple Splunk indexers.

B.

Use a Splunk indexer to collect a network input on port 514 directly.

C.

Use a Splunk forwarder to collect the input on port 514 and forward the data.

D.

Configure syslog to write logs and use a Splunk forwarder to collect the logs.

Full Access
Question # 54

When adding or rejoining a member to a search head cluster, the following error is displayed:

Error pulling configurations from the search head cluster captain; consider performing a destructive configuration resync on this search head cluster member.

What corrective action should be taken?

A.

Restart the search head.

B.

Run the splunk apply shcluster-bundle command from the deployer.

C.

Run the clean raft command on all members of the search head cluster.

D.

Run the splunk resync shcluster-replicated-config command on this member.

Full Access
Question # 55

(Which index does Splunk use to record user activities?)

A.

_internal

B.

_audit

C.

_kvstore

D.

_telemetry

Full Access
Question # 56

Which command will permanently decommission a peer node operating in an indexer cluster?

A.

splunk stop -f

B.

splunk offline -f

C.

splunk offline --enforce-counts

D.

splunk decommission --enforce counts

Full Access
Question # 57

(It is possible to lose UI edit functionality after manually editing which of the following files in the deployment server?)

A.

serverclass.conf

B.

deploymentclient.conf

C.

inputs.conf

D.

deploymentserver.conf

Full Access
Question # 58

By default, what happens to configurations in the local folder of each Splunk app when it is deployed to a search head cluster?

A.

The local folder is copied to the local folder on the search heads.

B.

The local folder is merged into the default folder and deployed to the search heads.

C.

Only certain . conf files in the local folder are deployed to the search heads.

D.

The local folder is ignored and only the default folder is copied to the search heads.

Full Access
Question # 59

At which default interval does metrics.log generate a periodic report regarding license utilization?

A.

10 seconds

B.

30 seconds

C.

60 seconds

D.

300 seconds

Full Access
Question # 60

Which of the following can a Splunk diag contain?

A.

Search history, Splunk users and their roles, running processes, indexed data

B.

Server specs, current open connections, internal Splunk log files, index listings

C.

KV store listings, internal Splunk log files, search peer bundles listings, indexed data

D.

Splunk platform configuration details, Splunk users and their roles, current open connections, index listings

Full Access