Splunk SPLK-2002 Practice Test - Questions Answers, Page 12
List of questions
Related questions
Why should intermediate forwarders be avoided when possible?
To minimize license usage and cost.
To decrease mean time between failures.
Because intermediate forwarders cannot be managed by a deployment server.
To eliminate potential performance bottlenecks.
A Splunk deployment is being architected and the customer will be using Splunk Enterprise Security (ES) and Splunk IT Service Intelligence (ITSI). Through data onboarding and sizing, it is determined that over 200 discrete KPIs will be tracked by ITSI and 1TB of data per day by ES. What topology ensures a scalable and performant deployment?
Two search heads, one for ITSI and one for ES.
Two search head clusters, one for ITSI and one for ES.
One search head cluster with both ITSI and ES installed.
One search head with both ITSI and ES installed.
How can internal logging levels in a Splunk environment be changed to troubleshoot an issue? (select all that apply)
Use the Monitoring Console (MC).
Use Splunk command line.
Use Splunk Web.
Edit log-local. cfg.
Other than high availability, which of the following is a benefit of search head clustering?
Allows indexers to maintain multiple searchable copies of all data.
Input settings are synchronized between search heads.
Fewer network ports are required to be opened between search heads.
Automatic replication of user knowledge objects.
By default, what happens to configurations in the local folder of each Splunk app when it is deployed to a search head cluster?
The local folder is copied to the local folder on the search heads.
The local folder is merged into the default folder and deployed to the search heads.
Only certain . conf files in the local folder are deployed to the search heads.
The local folder is ignored and only the default folder is copied to the search heads.
A Splunk environment collecting 10 TB of data per day has 50 indexers and 5 search heads. A single-site indexer cluster will be implemented. Which of the following is a best practice for added data resiliency?
Set the Replication Factor to 49.
Set the Replication Factor based on allowed indexer failure.
Always use the default Replication Factor of 3.
Set the Replication Factor based on allowed search head failure.
Which Splunk log file would be the least helpful in troubleshooting a crash?
splunk_instrumentation.log
splunkd_stderr.log
crash-2022-05-13-ll:42:57.1og
splunkd.log
Which of the following use cases would be made possible by multi-site clustering? (select all that apply)
Use blockchain technology to audit search activity from geographically dispersed data centers.
Enable a forwarder to send data to multiple indexers.
Greatly reduce WAN traffic by preferentially searching assigned site (search affinity).
Seamlessly route searches to a redundant site in case of a site failure.
Which of the following would be the least helpful in troubleshooting contents of Splunk configuration files?
crash logs
search.log
btool output
diagnostic logs
What is the expected minimum amount of storage required for data across an indexer cluster with the following input and parameters?
* Raw data = 15 GB per day
* Index files = 35 GB per day
* Replication Factor (RF) = 2
* Search Factor (SF) = 2
85 GB per day
50 GB per day
100 GB per day
65 GB per day
Question