Splunk SPLK-2002 Practice Test - Questions Answers, Page 11
List of questions
Related questions
Following Splunk recommendations, where could the Monitoring Console (MC) be installed in a distributed deployment with an indexer cluster, a search head cluster, and 1000 forwarders?
On a search peer in the cluster.
On the deployment server.
On the search head cluster deployer.
On a search head in the cluster.
A Splunk instance has crashed, but no crash log was generated. There is an attempt to determine what user activity caused the crash by running the following search:
What does searching for closed_txn=0 do in this search?
Filters results to situations where Splunk was started and stopped multiple times.
Filters results to situations where Splunk was started and stopped once.
Filters results to situations where Splunk was stopped and then immediately restarted.
Filters results to situations where Splunk was started, but not stopped.
The master node distributes configuration bundles to peer nodes. Which directory peer nodes receive the bundles?
apps
deployment-apps
slave-apps
master-apps
metrics. log is stored in which index?
main
_telemetry
_internal
_introspection
A single-site indexer cluster has a replication factor of 3, and a search factor of 2. What is true about this cluster?
The cluster will ensure there are at least two copies of each bucket, and at least three copies of searchable metadata.
The cluster will ensure there are at most three copies of each bucket, and at most two copies of searchable metadata.
The cluster will ensure only two search heads are allowed to access the bucket at the same time.
The cluster will ensure there are at least three copies of each bucket, and at least two copies of searchable metadata.
Which of the following configuration attributes must be set in server, conf on the cluster manager in a single-site indexer cluster?
master_uri
site
replication_factor
site_replication_factor
Which of the following most improves KV Store resiliency?
Decrease latency between search heads.
Add faster storage to the search heads to improve artifact replication.
Add indexer CPU and memory to decrease search latency.
Increase the size of the Operations Log.
Which of the following Splunk deployments has the recommended minimum components for a high-availability search head cluster?
2 search heads, 1 deployer, 2 indexers
3 search heads, 1 deployer, 3 indexers
1 search head, 1 deployer, 3 indexers
2 search heads, 1 deployer, 3 indexers
What is needed to ensure that high-velocity sources will not have forwarding delays to the indexers?
Increase the default value of sessionTimeout in server, conf.
Increase the default limit for maxKBps in limits.conf.
Decrease the value of forceTimebasedAutoLB in outputs. conf.
Decrease the default value of phoneHomelntervallnSecs in deploymentclient .conf.
Users who receive a link to a search are receiving an 'Unknown sid' error message when they open the link.
Why is this happening?
The users have insufficient permissions.
An add-on needs to be updated.
The search job has expired.
One or more indexers are down.
Question