New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Splunk SPLK-2002 Practice Exam with Questions & Answers | Set: 2

Questions 11

(Based on the data sizing and retention parameters listed below, which of the following will correctly calculate the index storage required?)

• Daily rate = 20 GB / day

• Compress factor = 0.5

• Retention period = 30 days

• Padding = 100 GB

Options:
A.

(20 * 30 + 100) * 0.5 = 350 GB

B.

20 / 0.5 * 30 + 100 = 1300 GB

C.

20 * 0.5 * 30 + 100 = 400 GB

D.

20 * 30 + 100 = 700 GB

Splunk SPLK-2002 Premium Access
Questions 12

New data has been added to a monitor input file. However, searches only show older data.

Which splunkd. log channel would help troubleshoot this issue?

Options:
A.

Modularlnputs

B.

TailingProcessor

C.

ChunkedLBProcessor

D.

ArchiveProcessor

Questions 13

(How is the search log accessed for a completed search job?)

Options:
A.

Search for: index=_internal sourcetype=search.

B.

Select Settings > Searches, reports, and alerts, then from the Actions column, select View Search Log.

C.

From the Activity menu, select Show Search Log.

D.

From the Job menu, select Inspect Job, then click the search.log link.

Questions 14

(What are the possible values for the mode attribute in server.conf for a Splunk server in the [clustering] stanza?)

Options:
A.

[clustering] mode = peer

B.

[clustering] mode = searchhead

C.

[clustering] mode = deployer

D.

[clustering] mode = manager

Questions 15

Which of the following is unsupported in a production environment?

Options:
A.

Cluster Manager can run on the Monitoring Console instance in smaller environments.

B.

Search Head Cluster Deployer can run on the Monitoring Console instance in smaller environments.

C.

Search heads in a Search Head Cluster can run on virtual machines.

D.

Indexers in an indexer cluster can run on virtual machines.

Questions 16

(When planning user management for a new Splunk deployment, which task can be disregarded?)

Options:
A.

Identify users authenticating with Splunk native authentication.

B.

Identify users authenticating with Splunk using LDAP or SAML.

C.

Determine the number of users present in Splunk log events.

D.

Determine the capabilities users need within the Splunk environment.

Questions 17

Which index-time props.conf attributes impact indexing performance? (Select all that apply.)

Options:
A.

REPORT

B.

LINE_BREAKER

C.

ANNOTATE_PUNCT

D.

SHOULD_LINEMERGE

Questions 18

When using ingest-based licensing, what Splunk role requires the license manager to scale?

Options:
A.

Search peers

B.

Search heads

C.

There are no roles that require the license manager to scale

D.

Deployment clients

Questions 19

Which of the following statements describe licensing in a clustered Splunk deployment? (Select all that apply.)

Options:
A.

Free licenses do not support clustering.

B.

Replicated data does not count against licensing.

C.

Each cluster member requires its own clustering license.

D.

Cluster members must share the same license pool and license master.

Questions 20

(Which of the following is not facilitated by the deployer?)

Options:
A.

Replication of knowledge objects.

B.

Deployment of baseline app configurations.

C.

Distribute non-replicated, non-runtime configuration updates.

D.

Migration of app and user configurations into the search head cluster.