Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Splunk SPLK-2002 Practice Exam with Questions & Answers | Set: 5

Questions 41

Which of the following is an indexer clustering requirement?

Options:
A.

Must use shared storage.

B.

Must reside on a dedicated rack.

C.

Must have at least three members.

D.

Must share the same license pool.

Splunk SPLK-2002 Premium Access
Questions 42

A new Splunk customer is using syslog to collect data from their network devices on port 514. What is the best practice for ingesting this data into Splunk?

Options:
A.

Configure syslog to send the data to multiple Splunk indexers.

B.

Use a Splunk indexer to collect a network input on port 514 directly.

C.

Use a Splunk forwarder to collect the input on port 514 and forward the data.

D.

Configure syslog to write logs and use a Splunk forwarder to collect the logs.

Questions 43

A single-site indexer cluster has a replication factor of 3, and a search factor of 2. What is true about this cluster?

Options:
A.

The cluster will ensure there are at least two copies of each bucket, and at least three copies of searchable metadata.

B.

The cluster will ensure there are at most three copies of each bucket, and at most two copies of searchable metadata.

C.

The cluster will ensure only two search heads are allowed to access the bucket at the same time.

D.

The cluster will ensure there are at least three copies of each bucket, and at least two copies of searchable metadata.

Questions 44

If .delta replication fails during knowledge bundle replication, what is the fall-back method for Splunk?

Options:
A.

.Restart splunkd.

B.

.delta replication.

C.

.bundle replication.

D.

Restart mongod.

Questions 45

As of Splunk 9.0, which index records changes to . conf files?

Options:
A.

_configtracker

B.

_introspection

C.

_internal

D.

_audit

Questions 46

Which of the following use cases would be made possible by multi-site clustering? (select all that apply)

Options:
A.

Use blockchain technology to audit search activity from geographically dispersed data centers.

B.

Enable a forwarder to send data to multiple indexers.

C.

Greatly reduce WAN traffic by preferentially searching assigned site (search affinity).

D.

Seamlessly route searches to a redundant site in case of a site failure.

Questions 47

When using the props.conf LINE_BREAKER attribute to delimit multi-line events, the SHOULD_LINEMERGE attribute should be set to what?

Options:
A.

Auto

B.

None

C.

True

D.

False

Questions 48

Which command will permanently decommission a peer node operating in an indexer cluster?

Options:
A.

splunk stop -f

B.

splunk offline -f

C.

splunk offline --enforce-counts

D.

splunk decommission --enforce counts