ExamGecko
Home Home / Splunk / SPLK-3002

Splunk SPLK-3002 Practice Test - Questions Answers, Page 3

Question list
Search
Search

Which scenario would benefit most by implementing ITSI?

A.
Monitoring of business services functionality.
A.
Monitoring of business services functionality.
Answers
B.
Monitoring of system hardware.
B.
Monitoring of system hardware.
Answers
C.
Monitoring of system process statuses
C.
Monitoring of system process statuses
Answers
D.
Monitoring of retail sales metrics.
D.
Monitoring of retail sales metrics.
Answers
Suggested answer: A

Explanation:

Splunk IT Service Intelligence (ITSI) is a monitoring and analytics solution that uses artificial intelligence and machine learning to provide insights into the health and performance of IT services. ITSI lets you create services that represent the critical components of your IT infrastructure, such as applications, databases, servers, networks, and so on. You can then monitor the status and performance of these services using key performance indicators (KPIs), which are metrics that measure aspects of service health, such as availability, latency, error rate, and so on. ITSI also provides tools for visualizing, investigating, and alerting on service issues, such as service analyzers, glass tables, deep dives, episode review, and so on. The scenario that would benefit most by implementing ITSI is monitoring of business service functionality, because ITSI enables you to measure and improve the quality and reliability of your IT services and align them with your business objectives.

Reference:What is Splunk IT Service Intelligence?

ITSI Saved Search Scheduling is configured to use realtime_schedule = 0. Which statement is accurate about this configuration?

A.
If this value is set to 0, the scheduler bases its determination of the next scheduled search execution time on the current time.
A.
If this value is set to 0, the scheduler bases its determination of the next scheduled search execution time on the current time.
Answers
B.
If this value is set to 0, the scheduler bases its determination of the next scheduled search on the last search execution time.
B.
If this value is set to 0, the scheduler bases its determination of the next scheduled search on the last search execution time.
Answers
C.
If this value is set to 0, the scheduler may skip scheduled execution periods.
C.
If this value is set to 0, the scheduler may skip scheduled execution periods.
Answers
D.
If this value is set to 0, the scheduler might skip some execution periods to make sure that the scheduler is executing the searches running over the most recent time range.
D.
If this value is set to 0, the scheduler might skip some execution periods to make sure that the scheduler is executing the searches running over the most recent time range.
Answers
Suggested answer: B

Explanation:

ITSI Saved Search Scheduling is a feature that allows you to schedule searches that run periodically to populate the data for your KPIs. You can configure various settings for your scheduled searches, such as the search frequency, the time range, the cron expression, and so on. One of the settings is realtime_schedule, which controls the way the scheduler computes the next execution time of a scheduled search. The statement that is accurate about this configuration is:

B) If this value is set to 0, the scheduler bases its determination of the next scheduled search on the last search execution time. This is called continuous scheduling. If set to 0, the scheduler never skips scheduled execution periods. However, the execution of the saved search might fall behind depending on the scheduler's load. Use continuous scheduling whenever you enable the summary index option.

The other statements are not accurate because:

A) If this value is set to 0, the scheduler bases its determination of the next scheduled search execution time on the current time. This is not true because this is what happens when the value is set to 1, not 0.

C) If this value is set to 0, the scheduler may skip scheduled execution periods. This is not true because this is what happens when the value is set to 1, not 0.

D) If this value is set to 0, the scheduler might skip some execution periods to make sure that the scheduler is executing the searches running over the most recent time range. This is not true because this is what happens when the value is set to 1, not 0.

For which ITSI function is it a best practice to use a 15-30 minute time buffer?

A.
Correlation searches.
A.
Correlation searches.
Answers
B.
Adaptive thresholding.
B.
Adaptive thresholding.
Answers
C.
Maintenance windows
C.
Maintenance windows
Answers
D.
Anomaly detection.
D.
Anomaly detection.
Answers
Suggested answer: B

Explanation:

B is the correct answer because adaptive thresholding is a feature of ITSI that allows you to dynamically adjust KPI thresholds based on historical patterns and trends. Adaptive thresholding requires a time buffer of at least 15 minutes to calculate the thresholds based on the previous data points. The time buffer ensures that there is enough data to perform the calculations and avoid false positives or negatives.

Reference:Configure adaptive thresholding for a KPI in ITSI

There are two departments using ITSI. Finance and Sales. Analysts in each department should not be allowed to see each other's services. What are the role configuration steps required to accomplish this?

A.
itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_analyst.
A.
itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_analyst.
Answers
B.
itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_team_analyst; itoa_sales_analyst, inherited from itoa_team_analyst.
B.
itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_team_analyst; itoa_sales_analyst, inherited from itoa_team_analyst.
Answers
C.
itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_team_analyst.
C.
itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_team_analyst.
Answers
D.
itoa_finance_admin, inherited from itoa_team_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_analyst.
D.
itoa_finance_admin, inherited from itoa_team_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_analyst.
Answers
Suggested answer: C

Explanation:

C is the correct answer because teams are a feature of ITSI that allow you to restrict access to service content in UI views based on user roles. To create separate teams for finance and sales analysts, you need to create custom roles that inherit from the itoa_analyst role, which has read-only access to ITSI content. For example, you can create itoa_finance_analyst and itoa_sales_analyst roles that inherit from itoa_analyst. Then, you need to create custom teams that include these roles and assign them to the relevant services. For example, you can create a finance team that includes the itoa_finance_analyst role and assign it to the finance services. Similarly, you can create a sales team that includes the itoa_sales_analyst role and assign it to the sales services. This way, analysts in each department can only see their own services and not each other's.

Reference:Create teams in ITSI,Assign teams to services in ITSI

How do you automatically restrict a KPI to only the entities in its service, and generate KPI values for each entity?

A.
Select ''Yes'' for both ''Split by Entity'' and ''Filter to Entities in Service''.
A.
Select ''Yes'' for both ''Split by Entity'' and ''Filter to Entities in Service''.
Answers
B.
Select ''No'' for ''Split by Entity'' and ''Yes'' for ''Filter to Entities in Service''.
B.
Select ''No'' for ''Split by Entity'' and ''Yes'' for ''Filter to Entities in Service''.
Answers
C.
Select ''Yes'' for ''Split by Entity'' and ''No'' for ''Filter to Entities in Service''.
C.
Select ''Yes'' for ''Split by Entity'' and ''No'' for ''Filter to Entities in Service''.
Answers
D.
Select ''No'' for both ''Split by Entity'' and ''Filter to Entities in Service''.
D.
Select ''No'' for both ''Split by Entity'' and ''Filter to Entities in Service''.
Answers
Suggested answer: A

Explanation:

A is the correct answer because selecting ''Yes'' for both ''Split by Entity'' and ''Filter to Entities in Service'' allows you to automatically restrict a KPI to only the entities in its service and generate KPI values for each entity. Split by Entity splits the KPI search results by entity alias fields and calculates a separate KPI value for each entity. Filter to Entities in Service filters out any entities that are not part of the service from the KPI search results. This way, you can ensure that your KPI reflects only the relevant entities for your service and provides granular information for each entity.

Reference: [Configure KPI settings in ITSI]

Which of the following items describe ITSI Backup and Restore functionality? (Choose all that apply.)

A.
A pre-configured default ITSI backup job is provided that can be modified, but not deleted.
A.
A pre-configured default ITSI backup job is provided that can be modified, but not deleted.
Answers
B.
ITSI backup is inclusive of KV Store, ITSI Configurations, and index dependencies.
B.
ITSI backup is inclusive of KV Store, ITSI Configurations, and index dependencies.
Answers
C.
kvstore_to_json.py can be used in scripts or command line to backup ITSI for full or partial backups.
C.
kvstore_to_json.py can be used in scripts or command line to backup ITSI for full or partial backups.
Answers
D.
ITSI backups are stored as a collection of JSON formatted files.
D.
ITSI backups are stored as a collection of JSON formatted files.
Answers
Suggested answer: C, D

Explanation:

ITSI provides akvstore_to_json.pyscript that lets you backup/restore ITSI configuration data, perform bulk service KPI operations, apply time zone offsets for ITSI objects, and regenerate KPI search schedules.

When you run a backup job, ITSI saves your data to a set of JSON files compressed into a single ZIP file.

https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/kvstorejson

https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/BackupandRestoreITSIconfig

C and D are correct answers because ITSI backup and restore functionality uses kvstore_to_json.py as a command line script or as part of custom scripts to backup ITSI data for full or partial backups. ITSI backups are also stored as a collection of JSON formatted files that contain KV store objects such as services, KPIs, glass tables, etc. A is not a correct answer because there is no pre-configured default ITSI backup job provided. You can create your own backup jobs or use the command line script or custom scripts to backup ITSI data. B is not a correct answer because ITSI backup is not inclusive of index dependencies. ITSI backup only includes KV store objects and optionally some .conf files. You need to use other methods to backup index data.

Reference: [Overview of backing up and restoring ITSI KV store data], [Create a full backup of ITSI], [Create a partial backup of ITSI]

When installing ITSI to support a Distributed Search Architecture, which of the following items apply? (Choose all that apply.)

A.
Copy SA-IndexCreation to all indexers.
A.
Copy SA-IndexCreation to all indexers.
Answers
B.
Copy SA-IndexCreation to the etc/apps directory on the index cluster master node.
B.
Copy SA-IndexCreation to the etc/apps directory on the index cluster master node.
Answers
C.
Extract installer package into etc/apps directory of the cluster deployer node.
C.
Extract installer package into etc/apps directory of the cluster deployer node.
Answers
D.
Extract ITSI app package into etc/apps directory of search head.
D.
Extract ITSI app package into etc/apps directory of search head.
Answers
Suggested answer: A

Explanation:

CopySA-IndexCreationto$SPLUNK_HOME/etc/apps/on all individual indexers in your environment.

A is the correct answer because when installing ITSI to support a distributed search architecture, you need to copy SA-IndexCreation to all indexers. SA-IndexCreation is an app that contains the definitions of the ITSI indexes, such as itsi_summary, itsi_tracked_alerts, itsi_grouped_alerts, etc. You need to copy this app to all indexers to ensure that they can store and search the ITSI data. B is not a correct answer because you do not need to copy SA-IndexCreation to the etc/apps directory on the index cluster master node. The index cluster master node does not store or search data, it only manages the replication and availability of data across the index cluster peers. C is not a correct answer because you do not need to extract the installer package into etc/apps directory of the cluster deployer node. The cluster deployer node is used to distribute apps and configuration updates to the search head cluster members. You need to extract the installer package into etc/shcluster/apps directory of the cluster deployer node instead. D is not a correct answer because you do not need to extract the ITSI app package into etc/apps directory of search head. You need to extract the ITSI app package into etc/shcluster/apps directory of the cluster deployer node and use the deployer to push the app to all search head cluster members.

Reference: [Install Splunk IT Service Intelligence on a search head cluster], [Install Splunk IT Service Intelligence on an indexer cluster]

Which of the following is a valid type of Multi-KPI Alert?

A.
Score over composite.
A.
Score over composite.
Answers
B.
Value over time.
B.
Value over time.
Answers
C.
Status over time.
C.
Status over time.
Answers
D.
Rise over run.
D.
Rise over run.
Answers
Suggested answer: B

Explanation:

B is the correct answer because value over time is a valid type of Multi-KPI Alert in ITSI. A Multi-KPI Alert is a type of alert that triggers when multiple KPIs from one or more services meet certain conditions within a specified time range. Value over time is a condition that compares the current value of a KPI to its previous values over a specified time range. For example, you can create a Multi-KPI Alert that triggers when the CPU usage and memory usage of a service are both higher than their average values in the last 24 hours.

Reference: [Create Multi-KPI alerts in ITSI], [Multi-KPI alert conditions in ITSI]

When must a service define entity rules?

A.
If the intention is for the KPIs in the service to filter to only entities assigned to the service.
A.
If the intention is for the KPIs in the service to filter to only entities assigned to the service.
Answers
B.
To enable entity cohesion anomaly detection.
B.
To enable entity cohesion anomaly detection.
Answers
C.
If some or all of the KPIs in the service will be split by entity.
C.
If some or all of the KPIs in the service will be split by entity.
Answers
D.
If the intention is for the KPIs in the service to have different aggregate vs. entity KPI values.
D.
If the intention is for the KPIs in the service to have different aggregate vs. entity KPI values.
Answers
Suggested answer: A

Explanation:

Provide a value to filter the service to a specific set of entities. These entity rule values are meant to be custom for each service.

A is the correct answer because a service must define entity rules if the intention is for the KPIs in the service to filter to only entities assigned to the service. Entity rules are filters that match entities to services based on entity aliases or entity metadata. If you enable the Filter to Entities in Service option for a KPI, you need to define entity rules for the service to ensure that the KPI search results only include the relevant entities for the service. Otherwise, the KPI search results might include entities that are not part of the service or exclude entities that are part of the service.

Reference: [Define entities for a service in ITSI], [Configure KPI settings in ITSI]

What effects does the KPI importance weight of 11 have on the overall health score of a service?

A.
At least 10% of the KPIs will go critical.
A.
At least 10% of the KPIs will go critical.
Answers
B.
Importance weight is unused for health scoring.
B.
Importance weight is unused for health scoring.
Answers
C.
The service will go critical.
C.
The service will go critical.
Answers
D.
It is a minimum health indicator KPI.
D.
It is a minimum health indicator KPI.
Answers
Suggested answer: B

Explanation:

The KPI importance weight is a value that indicates how much a KPI contributes to the overall health score of a service. The importance weight can range from 1 (lowest) to 10 (highest). The statement that applies when configuring a KPI importance weight of 11 is:

B) Importance weight is unused for health scoring. This is true because an importance weight of 11 is invalid and cannot be used for health scoring. The maximum value for importance weight is 10.

The other statements do not apply because:

A) At least 10% of the KPIs will go critical. This is not true because an importance weight of 11 does not affect the severity level of any KPIs.

C) The service will go critical. This is not true because an importance weight of 11 does not affect the health score or status of any service.

D) It is a minimum health indicator KPI. This is not true because an importance weight of 11 does not indicate anything about the minimum health level of a KPI.

Total 90 questions
Go to page: of 9