Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-2002 Practice Exam with Questions & Answers

Questions 1

Which command should be run to re-sync a stale KV Store member in a search head cluster?

Options:
A.

splunk clean kvstore -local

B.

splunk resync kvstore -remote

C.

splunk resync kvstore -local

D.

splunk clean eventdata -local

Splunk SPLK-2002 Premium Access
Questions 2

In the deployment planning process, when should a person identify who gets to see network data?

Options:
A.

Deployment schedule

B.

Topology diagramming

C.

Data source inventory

D.

Data policy definition

Questions 3

Which of the following are client filters available in serverclass.conf? (Select all that apply.)

Options:
A.

DNS name.

B.

IP address.

C.

Splunk server role.

D.

Platform (machine type).

Questions 4

What is the logical first step when starting a deployment plan?

Options:
A.

Inventory the currently deployed logging infrastructure.

B.

Determine what apps and use cases will be implemented.

C.

Gather statistics on the expected adoption of Splunk for sizing.

D.

Collect the initial requirements for the deployment from all stakeholders.

Questions 5

On search head cluster members, where in $splunk_home does the Splunk Deployer deploy app content by default?

Options:
A.

etc/apps/

B.

etc/slave-apps/

C.

etc/shcluster/

D.

etc/deploy-apps/

Questions 6

What information is needed about the current environment before deploying Splunk? (select all that apply)

Options:
A.

List of vendors for network devices.

B.

Overall goals for the deployment.

C.

Key users.

D.

Data sources.

Questions 7

In splunkd. log events written to the _internal index, which field identifies the specific log channel?

Options:
A.

component

B.

source

C.

sourcetype

D.

channel

Questions 8

In an existing Splunk environment, the new index buckets that are created each day are about half the size of the incoming data. Within each bucket, about 30% of the space is used for rawdata and about 70% for index files.

What additional information is needed to calculate the daily disk consumption, per indexer, if indexer clustering is implemented?

Options:
A.

Total daily indexing volume, number of peer nodes, and number of accelerated searches.

B.

Total daily indexing volume, number of peer nodes, replication factor, and search factor.

C.

Total daily indexing volume, replication factor, search factor, and number of search heads.

D.

Replication factor, search factor, number of accelerated searches, and total disk size across cluster.

Questions 9

Which search will show all deployment client messages from the client (UF)?

Options:
A.

index=_audit component=DC* host= | stats count by message

B.

index=_audit component=DC* host= | stats count by message

C.

index=_internal component= DC* host= | stats count by message

D.

index=_internal component=DS* host= | stats count by message

Questions 10

Which of the following describe migration from single-site to multisite index replication?

Options:
A.

A master node is required at each site.

B.

Multisite policies apply to new data only.

C.

Single-site buckets instantly receive the multisite policies.

D.

Multisite total values should not exceed any single-site factors.