ExamGecko
Home / Splunk / SPLK-3002 / Practice Test 2
Ask Question

Splunk SPLK-3002 Practice Test 2

Add to Whishlist
00:00:00
Show Answer
Report Issue   Restart test

Question 1 / 40

Where are KPI search results stored?

The default index.
The default index.
KV Store.
KV Store.
Output to a CSV lookup.
Output to a CSV lookup.
The itsi_summary index.
The itsi_summary index.
Comment (0)
Suggested answer: D
Explanation:

Search results are processed, created, and written to the itsi_summary index via an alert action.

D is the correct answer because KPI search results are stored in the itsi_summary index in ITSI. This index is an events index that stores the results of scheduled KPI searches. Summary indexing lets you run fast searches over large data sets by spreading out the cost of a computationally expensive report over time.

Reference:Overview of ITSI indexes

asked 23/09/2024
M S
38 questions