(On which Splunk components does the Splunk App for Enterprise Security place the most load?)
In which phase of the Splunk Enterprise data pipeline are indexed extraction configurations processed?
Which of the following strongly impacts storage sizing requirements for Enterprise Security?
Which of the following artifacts are included in a Splunk diag file? (Select all that apply.)
(An admin removed and re-added search head cluster (SHC) members as part of patching the operating system. When trying to re-add the first member, a script reverted the SHC member to a previous backup, and the member refuses to join the cluster. What is the best approach to fix the member so that it can re-join?)
How can internal logging levels in a Splunk environment be changed to troubleshoot an issue? (select all that apply)
(What is the expected performance reduction when architecting Splunk in a virtualized environment instead of a physical environment?)
Which command should be run to re-sync a stale KV Store member in a search head cluster?
To reduce the captain's work load in a search head cluster, what setting will prevent scheduled searches from running on the captain?
In the deployment planning process, when should a person identify who gets to see network data?
(Based on the data sizing and retention parameters listed below, which of the following will correctly calculate the index storage required?)
• Daily rate = 20 GB / day
• Compress factor = 0.5
• Retention period = 30 days
• Padding = 100 GB
Which of the following statements describe search head clustering? (Select all that apply.)
A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)
When preparing to ingest a new data source, which of the following is optional in the data source assessment?
(A customer has a Splunk Enterprise deployment and wants to collect data from universal forwarders. What is the best step to secure log traffic?)
Indexing is slow and real-time search results are delayed in a Splunk environment with two indexers and one search head. There is ample CPU and memory available on the indexers. Which of the following is most likely to improve indexing performance?
Consider a use case involving firewall data. There is no Splunk-supported Technical Add-On, but the vendor has built one. What are the items that must be evaluated before installing the add-on? (Select all that apply.)
Which of the following is a valid use case that a search head cluster addresses?
Which of the following server. conf stanzas indicates the Indexer Discovery feature has not been fully configured (restart pending) on the Master Node?
A)
B)
C)
D)
(A customer wishes to keep costs to a minimum, while still implementing Search Head Clustering (SHC). What are the minimum supported architecture standards?)
In an indexer cluster, what tasks does the cluster manager perform? (select all that apply)
A search head cluster with a KV store collection can be updated from where in the KV store collection?
(Which of the following is a valid way to determine if a new bundle push will trigger a rolling restart?)
A multi-site indexer cluster can be configured using which of the following? (Select all that apply.)
The master node distributes configuration bundles to peer nodes. Which directory peer nodes receive the bundles?
(Which btool command will identify license master configuration errors for a search peer cluster node?)
Which of the following statements describe licensing in a clustered Splunk deployment? (Select all that apply.)
Stakeholders have identified high availability for searchable data as their top priority. Which of the following best addresses this requirement?
Which of the following are possible causes of a crash in Splunk? (select all that apply)
A Splunk instance has crashed, but no crash log was generated. There is an attempt to determine what user activity caused the crash by running the following search:
What does searching for closed_txn=0 do in this search?
Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)
What does setting site=site0 on all Search Head Cluster members do in a multi-site indexer cluster?
The frequency in which a deployment client contacts the deployment server is controlled by what?
Because Splunk indexing is read/write intensive, it is important to select the appropriate disk storage solution for each deployment. Which of the following statements is accurate about disk storage?
Which server.conf attribute should be added to the master node's server.conf file when decommissioning a site in an indexer cluster?
How does the average run time of all searches relate to the available CPU cores on the indexers?
To optimize the distribution of primary buckets; when does primary rebalancing automatically occur? (Select all that apply.)
(Which command is used to initially add a search head to a single-site indexer cluster?)
To activate replication for an index in an indexer cluster, what attribute must be configured in indexes.conf on all peer nodes?
Which of the following tasks should the architect perform when building a deployment plan? (Select all that apply.)
Which tool(s) can be leveraged to diagnose connection problems between an indexer and forwarder? (Select all that apply.)
When converting from a single-site to a multi-site cluster, what happens to existing single-site clustered buckets?
A search head cluster member contains the following in its server .conf. What is the Splunk server name of this member?
(Where can files be placed in a configuration bundle on a search peer that will persist after a new configuration bundle has been deployed?)
Which of the following is true regarding Splunk Enterprise's performance? (Select all that apply.)
(How can a Splunk admin control the logging level for a specific search to get further debug information?)
When implementing KV Store Collections in a search head cluster, which of the following considerations is true?
In a distributed environment, knowledge object bundles are replicated from the search head to which location on the search peer(s)?
A customer has a multisite cluster with site1 and site2 configured. They want to configure search heads in these sites to get search results only from data stored on their local sites. Which step prevents this behavior?