Splunk SPLK-2002 Practice Test - Questions Answers, Page 11

List of questions
Question 101

Following Splunk recommendations, where could the Monitoring Console (MC) be installed in a distributed deployment with an indexer cluster, a search head cluster, and 1000 forwarders?
Question 102

A Splunk instance has crashed, but no crash log was generated. There is an attempt to determine what user activity caused the crash by running the following search:
What does searching for closed_txn=0 do in this search?
Question 103

The master node distributes configuration bundles to peer nodes. Which directory peer nodes receive the bundles?
Question 104

metrics. log is stored in which index?
Question 105

A single-site indexer cluster has a replication factor of 3, and a search factor of 2. What is true about this cluster?
Question 106

Which of the following configuration attributes must be set in server, conf on the cluster manager in a single-site indexer cluster?
Question 107

Which of the following most improves KV Store resiliency?
Question 108

Which of the following Splunk deployments has the recommended minimum components for a high-availability search head cluster?
Question 109

What is needed to ensure that high-velocity sources will not have forwarding delays to the indexers?
Question 110

Users who receive a link to a search are receiving an 'Unknown sid' error message when they open the link.
Why is this happening?
Question