Splunk SPLK-3002 Practice Test - Questions Answers, Page 5
Related questions
Where are KPI search results stored?
A.
The default index.
B.
KV Store.
C.
Output to a CSV lookup.
D.
The itsi_summary index.
Which ITSI functions generate notable events? (Choose all that apply.)
A.
KPI threshold breaches.
B.
KPI anomaly detection.
C.
Multi-KPI alert.
D.
Correlation search.
Which of the following describes a way to delete multiple duplicate entities in ITSI?
A.
Via c CSV upload.
B.
Via the entity lister page.
C.
Via a search using the | deleteentity command.
D.
All of the above.
Which capabilities are enabled through ''teams''?
A.
Teams allow searches against the itsi_summary index.
B.
Teams restrict notable event alert actions.
C.
Teams restrict searches against the itsi_notable_audit index.
D.
Teams allow restrictions to service content in UI views.
Besides creating notable events, what are the default alert actions a correlation search can execute? (Choose all that apply.)
A.
Ping a host.
B.
Send email.
C.
Include in RSS feed.
D.
Run a script.
Within a correlation search, dynamic field values can be specified with what syntax?
A.
fieldname
B.
<fieldname /fieldname>
C.
%fieldname%
D.
eval(fieldname)
In maintenance mode, which features of KPIs still function?
A.
KPI searches will execute but will be buffered until the maintenance window is over.
B.
KPI searches still run during maintenance mode, but results go to itsi_maintenance_summary index.
C.
New KPIs can be created, but existing KPIs are locked.
D.
KPI calculations and threshold settings can be modified.
Which index contains ITSI Episodes?
A.
itsi_tracked_alerts
B.
itsi_grouped_alerts
C.
itsi_notable_archive
D.
itsi_summary
Which of the following best describes a default deep dive?
A.
It initially shows the health scores for all services.
B.
It initially shows the highest importance KPIs.
C.
It initially shows all of the KPIs for a selected service.
D.
It initially shows all the entity swim lanes.
Which of the following describes enabling smart mode for an aggregation policy?
A.
Configure --> Policies --> Smart Mode --> Enable, select ''fields'', click ''Save''
B.
Enable grouping in Notable Event Review, select ''Smart Mode'', select ''fields'', and click ''Save''
C.
Edit the aggregation policy, enable smart mode, select fields to analyze, click ''Save''
D.
Edit the notable event view, enable smart mode, select ''fields'', and click ''Save''
Question