Splunk SPLK-2002 Practice Test - Questions Answers, Page 13

List of questions
Question 121

A monitored log file is changing on the forwarder. However, Splunk searches are not finding any new data that has been added. What are possible causes? (select all that apply)
Question 122

Which of the following is a problem that could be investigated using the Search Job Inspector?
Question 123

When troubleshooting a situation where some files within a directory are not being indexed, the ignored files are discovered to have long headers. What is the first thing that should be added to inputs.conf?
Question 124

In an indexer cluster, what tasks does the cluster manager perform? (select all that apply)
Question 125

New data has been added to a monitor input file. However, searches only show older data.
Which splunkd. log channel would help troubleshoot this issue?
Question 126

Determining data capacity for an index is a non-trivial exercise. Which of the following are possible considerations that would affect daily indexing volume? (select all that apply)
Question 127

Splunk Enterprise performs a cyclic redundancy check (CRC) against the first and last bytes to prevent the same file from being re-indexed if it is rotated or renamed. What is the number of bytes sampled by default?
Question 128

Users are asking the Splunk administrator to thaw recently-frozen buckets very frequently. What could the Splunk administrator do to reduce the need to thaw buckets?
Question 129

When should a dedicated deployment server be used?
Question 130

Which Splunk internal field can confirm duplicate event issues from failed file monitoring?
Question