Big 11.11 Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-2002 Practice Exam with Questions & Answers

Questions 1

As of Splunk 9.0, which index records changes to . conf files?

Options:
A.

_configtracker

B.

_introspection

C.

_internal

D.

_audit

Splunk SPLK-2002 Premium Access
Questions 2

(How can a Splunk admin control the logging level for a specific search to get further debug information?)

Options:
A.

Configure infocsv_log_level = DEBUG in limits.conf.

B.

Insert | noop log_debug=* after the base search.

C.

Open the Search Job Inspector in Splunk Web and modify the log level.

D.

Use Settings > Server settings > Server logging in Splunk Web.

Questions 3

What information is written to the __introspection log file?

Options:
A.

File monitor input configurations.

B.

File monitor checkpoint offset.

C.

User activities and knowledge objects.

D.

KV store performance.

Questions 4

Which of the following tasks should the architect perform when building a deployment plan? (Select all that apply.)

Options:
A.

Use case checklist.

B.

Install Splunk apps.

C.

Inventory data sources.

D.

Review network topology.

Questions 5

Users are asking the Splunk administrator to thaw recently-frozen buckets very frequently. What could the Splunk administrator do to reduce the need to thaw buckets?

Options:
A.

Change f rozenTimePeriodlnSecs to a larger value.

B.

Change maxTotalDataSizeMB to a smaller value.

C.

Change maxHotSpanSecs to a larger value.

D.

Change coldToFrozenDir to a different location.

Questions 6

Which search head cluster component is responsible for pushing knowledge bundles to search peers, replicating configuration changes to search head cluster members, and scheduling jobs across the search head cluster?

Options:
A.

Master

B.

Captain

C.

Deployer

D.

Deployment server

Questions 7

(Which of the following data sources are used for the Monitoring Console dashboards?)

Options:
A.

REST API calls

B.

Splunk btool

C.

Splunk diag

D.

metrics.log

Questions 8

Where does the Splunk deployer send apps by default?

Options:
A.

etc/slave-apps/<app-name>/default

B.

etc/deploy-apps/<app-name>/default

C.

etc/apps/<appname>/default

D.

etc/shcluster/<app-name>/default

Questions 9

Which of the following is true regarding the migration of an index cluster from single-site to multi-site?

Options:
A.

Multi-site policies will apply to all data in the indexer cluster.

B.

All peer nodes must be running the same version of Splunk.

C.

Existing single-site attributes must be removed.

D.

Single-site buckets cannot be converted to multi-site buckets.

Questions 10

Before users can use a KV store, an admin must create a collection. Where is a collection is defined?

Options:
A.

kvstore.conf

B.

collection.conf

C.

collections.conf

D.

kvcollections.conf