Splunk SPLK-3002 Practice Test - Questions Answers, Page 6
Related questions
Which of the following are the default ports that must be configured on Splunk to use ITSI?
A.
SplunkWeb (8405), SplunkD (8519), and HTTP Collector (8628)
B.
SplunkWeb (8089), SplunkD (8088), and HTTP Collector (8000)
C.
SplunkWeb (8000), SplunkD (8089), and HTTP Collector (8088)
D.
SplunkWeb (8088), SplunkD (8089), and HTTP Collector (8000)
Which of the following is a good use case regarding defining entities for a service?
A.
Automatically associate entities to services using multiple entity aliases.
B.
All of the entities have the same identifying field name.
C.
Being able to split a CPU usage KPI by host name.
D.
KPI total values are aggregated from multiple different category values in the source events.
When in maintenance mode, which of the following is accurate?
A.
Once the window is over, KPIs and notable events will begin to be generated again.
B.
KPIs are shown in blue while in maintenance mode.
C.
Maintenance mode slots are scheduled on a per hour basis.
D.
Service health scores and KPI events are deleted until the window is over.
In which index are active notable events stored?
A.
itsi_notable_archive
B.
itsi_notable_audit
C.
itsi_tracked_alerts
D.
itsi_tracked_groups
When a KPI's aggregate value is calculated, which function is called?
A.
stats
B.
tstats
C.
fieldsummary
D.
eval
Which of the following describes default deep dives?
A.
Are manually generated and can be accessed via the Service Analyzer.
B.
Include all KPIs of all services.
C.
Are auto-generated and can be accessed via the Service Analyzer.
D.
Include health scores of all services.
Which of the following is a problem requiring correction in ITSI?
A.
Two or more entities with the same service ID.
B.
Two or more entities with the same entity ID.
C.
Two or more entities with the same value in a single alias field.
D.
Two or more entities with the same entity key value in any info field.
Which of the following is a good use case for a Multi-KPI alert?
A.
Alerting when the values of two or more KPIs go into maintenance mode.
B.
Alerting when the trend of two or more KPIs indicates service failure is imminent.
C.
Alerting when two or more KPIs are deviating from their typical pattern.
D.
Alerting when comparing the values of two or more KPIs indicates an unusual condition is occurring.
Which of the following actions can be performed with a deep dive?
A.
Create a Multi-KPI alert from the deep dive's current state to warn of similar situations in the future.
B.
Create a predictive analysis model from the deep dive to warn of future service degradation.
C.
Create an anomaly detection alert to show when the same pattern begins in the future.
D.
Create a custom service analyzer from selected deep dive lanes.
Which of the following is an advantage of an adaptive time threshold?
A.
Automatically alerting when KPI value patterns change over time.
B.
Automatically adjusting thresholds as normal KPI values change over time.
C.
Automatically adjusting to holiday schedules.
D.
Automatically predicting future degradation of KPI values over time.
Question