Splunk SPLK-2002 Practice Test - Questions Answers, Page 11
List of questions
Question 101
Following Splunk recommendations, where could the Monitoring Console (MC) be installed in a distributed deployment with an indexer cluster, a search head cluster, and 1000 forwarders?
Question 102
A Splunk instance has crashed, but no crash log was generated. There is an attempt to determine what user activity caused the crash by running the following search:
What does searching for closed_txn=0 do in this search?
Question 103
The master node distributes configuration bundles to peer nodes. Which directory peer nodes receive the bundles?
Question 104
metrics. log is stored in which index?
Question 105
A single-site indexer cluster has a replication factor of 3, and a search factor of 2. What is true about this cluster?
Question 106
Which of the following configuration attributes must be set in server, conf on the cluster manager in a single-site indexer cluster?
Question 107
Which of the following most improves KV Store resiliency?
Question 108
Which of the following Splunk deployments has the recommended minimum components for a high-availability search head cluster?
Question 109
What is needed to ensure that high-velocity sources will not have forwarding delays to the indexers?
Question 110
Users who receive a link to a search are receiving an 'Unknown sid' error message when they open the link.
Why is this happening?
Question