Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Splunk SPLK-2002 Practice Exam with Questions & Answers | Set: 3

Questions 21

(Which index does Splunk use to record user activities?)

Options:
A.

_internal

B.

_audit

C.

_kvstore

D.

_telemetry

Splunk SPLK-2002 Premium Access
Questions 22

Which of the following configuration attributes must be set in server, conf on the cluster manager in a single-site indexer cluster?

Options:
A.

master_uri

B.

site

C.

replication_factor

D.

site_replication_factor

Questions 23

Which of the following describe migration from single-site to multisite index replication?

Options:
A.

A master node is required at each site.

B.

Multisite policies apply to new data only.

C.

Single-site buckets instantly receive the multisite policies.

D.

Multisite total values should not exceed any single-site factors.

Questions 24

To reduce the captain's work load in a search head cluster, what setting will prevent scheduled searches from running on the captain?

Options:
A.

adhoc_searchhead = true (on all members)

B.

adhoc_searchhead = true (on the current captain)

C.

captain_is_adhoc_searchhead = true (on all members)

D.

captain_is_adhoc_searchhead = true (on the current captain)

Questions 25

Which search head cluster component is responsible for pushing knowledge bundles to search peers, replicating configuration changes to search head cluster members, and scheduling jobs across the search head cluster?

Options:
A.

Master

B.

Captain

C.

Deployer

D.

Deployment server

Questions 26

(Which of the following data sources are used for the Monitoring Console dashboards?)

Options:
A.

REST API calls

B.

Splunk btool

C.

Splunk diag

D.

metrics.log

Questions 27

How can internal logging levels in a Splunk environment be changed to troubleshoot an issue? (select all that apply)

Options:
A.

Use the Monitoring Console (MC).

B.

Use Splunk command line.

C.

Use Splunk Web.

D.

Edit log-local. cfg.

Questions 28

When troubleshooting a situation where some files within a directory are not being indexed, the ignored files are discovered to have long headers. What is the first thing that should be added to inputs.conf?

Options:
A.

Decrease the value of initCrcLength.

B.

Add a crcSalt=<string> attribute.

C.

Increase the value of initCrcLength.

D.

Add a crcSalt= attribute.

Questions 29

The master node distributes configuration bundles to peer nodes. Which directory peer nodes receive the bundles?

Options:
A.

apps

B.

deployment-apps

C.

slave-apps

D.

master-apps

Questions 30

Because Splunk indexing is read/write intensive, it is important to select the appropriate disk storage solution for each deployment. Which of the following statements is accurate about disk storage?

Options:
A.

High performance SAN should never be used.

B.

Enable NFS for storing hot and warm buckets.

C.

The recommended RAID setup is RAID 10 (1 + 0).

D.

Virtualized environments are usually preferred over bare metal for Splunk indexers.