SPLK-2002 Splunk Enterprise Certified Architect Questions and Answers
Which of the following clarification steps should be taken if apps are not appearing on a deployment client? (Select all that apply.)
The master node distributes configuration bundles to peer nodes. Which directory peer nodes receive the bundles?
A multi-site indexer cluster can be configured using which of the following? (Select all that apply.)
Which of the following are client filters available in serverclass.conf? (Select all that apply.)
When Splunk indexes data in a non-clustered environment, what kind of files does it create by default?
An indexer cluster is being designed with the following characteristics:
• 10 search peers
• Replication Factor (RF): 4
• Search Factor (SF): 3
• No SmartStore usage
How many search peers can fail before data becomes unsearchable?
The frequency in which a deployment client contacts the deployment server is controlled by what?
An index has large text log entries with many unique terms in the raw data. Other than the raw data, which index components will take the most space?
When designing the number and size of indexes, which of the following considerations should be applied?
(It is possible to lose UI edit functionality after manually editing which of the following files in the deployment server?)
Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)
Which Splunk tool offers a health check for administrators to evaluate the health of their Splunk deployment?
Splunk Enterprise platform instrumentation refers to data that the Splunk Enterprise deployment logs in the _introspection index. Which of the following logs are included in this index? (Select all that apply.)
A customer is migrating 500 Universal Forwarders from an old deployment server to a new deployment server, with a different DNS name. The new deployment server is configured and running.
The old deployment server deployed an app containing an updated deploymentclient.conf file to all forwarders, pointing them to the new deployment server. The app was successfully deployed to all 500 forwarders.
Why would all of the forwarders still be phoning home to the old deployment server?
How can internal logging levels in a Splunk environment be changed to troubleshoot an issue? (select all that apply)
Which index-time props.conf attributes impact indexing performance? (Select all that apply.)
(An admin removed and re-added search head cluster (SHC) members as part of patching the operating system. When trying to re-add the first member, a script reverted the SHC member to a previous backup, and the member refuses to join the cluster. What is the best approach to fix the member so that it can re-join?)
Following Splunk recommendations, where could the Monitoring Console (MC) be installed in a distributed deployment with an indexer cluster, a search head cluster, and 1000 forwarders?
Configurations from the deployer are merged into which location on the search head cluster member?
(A high-volume source and a low-volume source feed into the same index. Which of the following items best describe the impact of this design choice?)
(Based on the data sizing and retention parameters listed below, which of the following will correctly calculate the index storage required?)
• Daily rate = 20 GB / day
• Compress factor = 0.5
• Retention period = 30 days
• Padding = 100 GB
When troubleshooting a situation where some files within a directory are not being indexed, the ignored files are discovered to have long headers. What is the first thing that should be added to inputs.conf?
If .delta replication fails during knowledge bundle replication, what is the fall-back method for Splunk?
Which of the following Splunk deployments has the recommended minimum components for a high-availability search head cluster?
Several critical searches that were functioning correctly yesterday are not finding a lookup table today. Which log file would be the best place to start troubleshooting?
Which of the following statements describe a Search Head Cluster (SHC) captain? (Select all that apply.)
Stakeholders have identified high availability for searchable data as their top priority. Which of the following best addresses this requirement?
(If a license peer cannot communicate to a license manager for 72 hours or more, what will happen?)
Which of the following is true regarding Splunk Enterprise's performance? (Select all that apply.)
In splunkd. log events written to the _internal index, which field identifies the specific log channel?
Which server.conf attribute should be added to the master node's server.conf file when decommissioning a site in an indexer cluster?
(A customer wishes to keep costs to a minimum, while still implementing Search Head Clustering (SHC). What are the minimum supported architecture standards?)
(Which indexes.conf attribute would prevent an index from participating in an indexer cluster?)
Which of the following statements describe search head clustering? (Select all that apply.)
What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza?
Because Splunk indexing is read/write intensive, it is important to select the appropriate disk storage solution for each deployment. Which of the following statements is accurate about disk storage?
New data has been added to a monitor input file. However, searches only show older data.
Which splunkd. log channel would help troubleshoot this issue?
(Which of the following is a minimum search head specification for a distributed Splunk environment?)
Which Splunk internal field can confirm duplicate event issues from failed file monitoring?
In a distributed environment, knowledge object bundles are replicated from the search head to which location on the search peer(s)?
(Which command is used to initially add a search head to a single-site indexer cluster?)
Which of the following use cases would be made possible by multi-site clustering? (select all that apply)
What is needed to ensure that high-velocity sources will not have forwarding delays to the indexers?
A Splunk instance has crashed, but no crash log was generated. There is an attempt to determine what user activity caused the crash by running the following search:
What does searching for closed_txn=0 do in this search?