Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpt65

SPLK-3003 Questions and Answers

Question # 6

A customer has been using Splunk for one year, utilizing a single/all-in-one instance. This single Splunk server is now struggling to cope with the daily ingest rate. Also, Splunk has become a vital system in day-to-day operations making high availability a consideration for the Splunk service. The customer is unsure how to design the new environment topology in order to provide this.

Which resource would help the customer gather the requirements for their new architecture?

A.

Direct the customer to the docs.splunk.com and tell them that all the information to help them select the right design is documented there.

B.

Ask the customer to engage with the sales team immediately as they probably need a larger license.

C.

Refer the customer to answers.splunk.com as someone else has probably already designed a system that meets their requirements.

D.

Refer the customer to the Splunk Validated Architectures document in order to guide them through which approved architectures could meet their requirements.

Full Access
Question # 7

What is the Splunk PS recommendation when using the deployment server and building deployment apps?

A.

Carefully design smaller apps with specific configuration that can be reused.

B.

Only deploy Splunk PS base configurations via the deployment server.

C.

Use $SPLUNK_HOME/etc/system/local configurations on forwarders and only deploy TAs via the deployment server.

D.

Carefully design bigger apps containing multiple configs.

Full Access
Question # 8

Which of the following statements is true, as it pertains to search head clustering (SHC)?

A.

SHC is supported on AIX, Linux, and Windows operating systems.

B.

Maximum number of nodes for a SHC is 10.

C.

SHC members must run on the same hardware specifications.

D.

Minimum number of nodes for a SHC is 5.

Full Access
Question # 9

Which of the following is the most efficient search?

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 10

The customer has an indexer cluster supporting a wide variety of search needs, including scheduled search, data model acceleration, and summary indexing. Here is an excerpt from the cluster mater’s server.conf:

Which strategy represents the minimum and least disruptive change necessary to protect the searchability of the indexer cluster in case of indexer failure?

A.

Enable maintenance mode on the CM to prevent excessive fix-up and bring the failed indexer back online.

B.

Leave replication_factor=2, increase search_factor=2 and enable summary_replication.

C.

Convert the cluster to multi-site and modify the server.conf to be site_replication_factor=2, site_search_factor=2.

D.

Increase replication_factor=3, search_factor=2 to protect the data, and allow there to always be a searchable copy.

Full Access
Question # 11

In addition to the normal responsibilities of a search head cluster captain, which of the following is a default behavior?

A.

The captain is not a cluster member and does not perform normal search activities.

B.

The captain is a cluster member who performs normal search activities.

C.

The captain is not a cluster member but does perform normal search activities.

D.

The captain is a cluster member but does not perform normal search activities.

Full Access
Question # 12

A site from a multi-site indexer cluster needs to be decommissioned. Which of the following actions must be taken?

A.

Nothing. Decommissioning a site is not possible.

B.

Create an alias for where the new data should be sent.

C.

Remove the site from the list of available sites.

D.

Remove the site from the list of available sites and create an alias for where the new data should be sent.

Full Access