New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Splunk SPLK-2002 Practice Exam with Questions & Answers

Questions 1

When troubleshooting monitor inputs, which command checks the status of the tailed files?

Options:
A.

splunk cmd btool inputs list | tail

B.

splunk cmd btool check inputs layer

C.

curl https://serverhost:8089/services/admin/inputstatus/TailingProcessor:FileStatus

D.

curl https://serverhost:8089/services/admin/inputstatus/TailingProcessor:Tailstatus

Splunk SPLK-2002 Premium Access
Questions 2

Of the following types of files within an index bucket, which file type may consume the most disk?

Options:
A.

Rawdata

B.

Bloom filter

C.

Metadata (.data)

D.

Inverted index (.tsidx)

Questions 3

Before users can use a KV store, an admin must create a collection. Where is a collection is defined?

Options:
A.

kvstore.conf

B.

collection.conf

C.

collections.conf

D.

kvcollections.conf

Questions 4

A search head cluster member contains the following in its server .conf. What is the Splunk server name of this member?

SPLK-2002 Question 4

Options:
A.

node1

B.

shc4

C.

idxc2

D.

node3

Questions 5

When Splunk is installed, where are the internal indexes stored by default?

Options:
A.

SPLUNK_HOME/bin

B.

SPLUNK_HOME/var/lib

C.

SPLUNK_HOME/var/run

D.

SPLUNK_HOME/etc/system/default

Questions 6

(What is a recommended way to improve search performance?)

Options:
A.

Use the shortest query possible.

B.

Filter as much as possible in the initial search.

C.

Use non-streaming commands as early as possible.

D.

Leverage the not expression to limit returned results.

Questions 7

When planning a search head cluster, which of the following is true?

Options:
A.

All search heads must use the same operating system.

B.

All search heads must be members of the cluster (no standalone search heads).

C.

The search head captain must be assigned to the largest search head in the cluster.

D.

All indexers must belong to the underlying indexer cluster (no standalone indexers).

Questions 8

Users who receive a link to a search are receiving an "Unknown sid" error message when they open the link.

Why is this happening?

Options:
A.

The users have insufficient permissions.

B.

An add-on needs to be updated.

C.

The search job has expired.

D.

One or more indexers are down.

Questions 9

In which phase of the Splunk Enterprise data pipeline are indexed extraction configurations processed?

Options:
A.

Input

B.

Search

C.

Parsing

D.

Indexing

Questions 10

A Splunk environment collecting 10 TB of data per day has 50 indexers and 5 search heads. A single-site indexer cluster will be implemented. Which of the following is a best practice for added data resiliency?

Options:
A.

Set the Replication Factor to 49.

B.

Set the Replication Factor based on allowed indexer failure.

C.

Always use the default Replication Factor of 3.

D.

Set the Replication Factor based on allowed search head failure.