Splunk SPLK-2002 Practice Test - Questions Answers, Page 13
List of questions
Related questions
A monitored log file is changing on the forwarder. However, Splunk searches are not finding any new data that has been added. What are possible causes? (select all that apply)
An admin ran splunk clean eventdata -index <indexname> on the indexer.
An admin has removed the Splunk fishbucket on the forwarder.
The last 256 bytes of the monitored file are not changing.
The first 256 bytes of the monitored file are not changing.
Which of the following is a problem that could be investigated using the Search Job Inspector?
Error messages are appearing underneath the search bar in Splunk Web.
Dashboard panels are showing 'Waiting for queued job to start' on page load.
Different users are seeing different extracted fields from the same search.
Events are not being sorted in reverse chronological order.
When troubleshooting a situation where some files within a directory are not being indexed, the ignored files are discovered to have long headers. What is the first thing that should be added to inputs.conf?
Decrease the value of initCrcLength.
Add a crcSalt=<string> attribute.
Increase the value of initCrcLength.
Add a crcSalt=<SOURCE> attribute.
In an indexer cluster, what tasks does the cluster manager perform? (select all that apply)
Generates and maintains the list of primary searchable buckets.
If Indexer Discovery is enabled, provides the list of available peer nodes to forwarders.
Ensures all peer nodes are always using the same version of Splunk.
Distributes app bundles to peer nodes.
New data has been added to a monitor input file. However, searches only show older data.
Which splunkd. log channel would help troubleshoot this issue?
Modularlnputs
TailingProcessor
ChunkedLBProcessor
ArchiveProcessor
Determining data capacity for an index is a non-trivial exercise. Which of the following are possible considerations that would affect daily indexing volume? (select all that apply)
Average size of event data.
Number of data sources.
Peak data rates.
Number of concurrent searches on data.
Splunk Enterprise performs a cyclic redundancy check (CRC) against the first and last bytes to prevent the same file from being re-indexed if it is rotated or renamed. What is the number of bytes sampled by default?
128
512
256
64
Users are asking the Splunk administrator to thaw recently-frozen buckets very frequently. What could the Splunk administrator do to reduce the need to thaw buckets?
Change f rozenTimePeriodlnSecs to a larger value.
Change maxTotalDataSizeMB to a smaller value.
Change maxHotSpanSecs to a larger value.
Change coldToFrozenDir to a different location.
When should a dedicated deployment server be used?
When there are more than 50 search peers.
When there are more than 50 apps to deploy to deployment clients.
When there are more than 50 deployment clients.
When there are more than 50 server classes.
Which Splunk internal field can confirm duplicate event issues from failed file monitoring?
_time
_indextime
_index_latest
latest
Question