Splunk SPLK-2002 Practice Test - Questions Answers, Page 2
List of questions
Related questions
What does the deployer do in a Search Head Cluster (SHC)? (Select all that apply.)
Distributes apps to SHC members.
Bootstraps a clean Splunk install for a SHC.
Distributes non-search-related and manual configuration file changes.
Distributes runtime knowledge object changes made by users across the SHC.
When using the props.conf LINE_BREAKER attribute to delimit multi-line events, the SHOULD_LINEMERGE attribute should be set to what?
Auto
None
True
False
Which of the following should be included in a deployment plan?
Business continuity and disaster recovery plans.
Current logging details and data source inventory.
Current and future topology diagrams of the IT environment.
A comprehensive list of stakeholders, either direct or indirect.
A multi-site indexer cluster can be configured using which of the following? (Select all that apply.)
Via Splunk Web.
Directly edit SPLUNK_HOME/etc./system/local/server.conf
Run a Splunk edit cluster-config command from the CLI.
Directly edit SPLUNK_HOME/etc/system/default/server.conf
Which index-time props.conf attributes impact indexing performance? (Select all that apply.)
REPORT
LINE_BREAKER
ANNOTATE_PUNCT
SHOULD_LINEMERGE
Which of the following are client filters available in serverclass.conf? (Select all that apply.)
DNS name.
IP address.
Splunk server role.
Platform (machine type).
What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza?
btool.log
metrics.log
splunkd.log
tailing_processor.log
Which Splunk tool offers a health check for administrators to evaluate the health of their Splunk deployment?
btool
DiagGen
SPL Clinic
Monitoring Console
In a four site indexer cluster, which configuration stores two searchable copies at the origin site, one searchable copy at site2, and a total of four searchable copies?
site_search_factor = origin:2, site1:2, total:4
site_search_factor = origin:2, site2:1, total:4
site_replication_factor = origin:2, site1:2, total:4
site_replication_factor = origin:2, site2:1, total:4
Which of the following is true regarding Splunk Enterprise's performance? (Select all that apply.)
Adding search peers increases the maximum size of search results.
Adding RAM to existing search heads provides additional search capacity.
Adding search peers increases the search throughput as the search load increases.
Adding search heads provides additional CPU cores to run more concurrent searches.
Question