ExamGecko
Home / Splunk / SPLK-2002 / List of questions
Ask Question

Splunk SPLK-2002 Practice Test - Questions Answers, Page 13

Add to Whishlist

List of questions

Question 121

Report Export Collapse

A monitored log file is changing on the forwarder. However, Splunk searches are not finding any new data that has been added. What are possible causes? (select all that apply)

Become a Premium Member for full access
  Unlock Premium Member

Question 122

Report Export Collapse

Which of the following is a problem that could be investigated using the Search Job Inspector?

Become a Premium Member for full access
  Unlock Premium Member

Question 123

Report Export Collapse

When troubleshooting a situation where some files within a directory are not being indexed, the ignored files are discovered to have long headers. What is the first thing that should be added to inputs.conf?

Become a Premium Member for full access
  Unlock Premium Member

Question 124

Report Export Collapse

In an indexer cluster, what tasks does the cluster manager perform? (select all that apply)

Become a Premium Member for full access
  Unlock Premium Member

Question 125

Report Export Collapse

New data has been added to a monitor input file. However, searches only show older data.

Which splunkd. log channel would help troubleshoot this issue?

Become a Premium Member for full access
  Unlock Premium Member

Question 126

Report Export Collapse

Determining data capacity for an index is a non-trivial exercise. Which of the following are possible considerations that would affect daily indexing volume? (select all that apply)

Become a Premium Member for full access
  Unlock Premium Member

Question 127

Report Export Collapse

Splunk Enterprise performs a cyclic redundancy check (CRC) against the first and last bytes to prevent the same file from being re-indexed if it is rotated or renamed. What is the number of bytes sampled by default?

Become a Premium Member for full access
  Unlock Premium Member

Question 128

Report Export Collapse

Users are asking the Splunk administrator to thaw recently-frozen buckets very frequently. What could the Splunk administrator do to reduce the need to thaw buckets?

Become a Premium Member for full access
  Unlock Premium Member

Question 129

Report Export Collapse

When should a dedicated deployment server be used?

Become a Premium Member for full access
  Unlock Premium Member

Question 130

Report Export Collapse

Which Splunk internal field can confirm duplicate event issues from failed file monitoring?

Become a Premium Member for full access
  Unlock Premium Member
Total 160 questions
Go to page: of 16
Search