Splunk SPLK-2002 Practice Test - Questions Answers, Page 7
List of questions
Related questions
Which command is used for thawing the archive bucket?
Splunk collect
Splunk convert
Splunk rebuild
Splunk dbinspect
When planning a search head cluster, which of the following is true?
All search heads must use the same operating system.
All search heads must be members of the cluster (no standalone search heads).
The search head captain must be assigned to the largest search head in the cluster.
All indexers must belong to the underlying indexer cluster (no standalone indexers).
In which phase of the Splunk Enterprise data pipeline are indexed extraction configurations processed?
Input
Search
Parsing
Indexing
Which server.conf attribute should be added to the master node's server.conf file when decommissioning a site in an indexer cluster?
site_mappings
available_sites
site_search_factor
site_replication_factor
Which tool(s) can be leveraged to diagnose connection problems between an indexer and forwarder? (Select all that apply.)
telnet
tcpdump
splunk btool
splunk btprobe
A search head has successfully joined a single site indexer cluster. Which command is used to configure the same search head to join another indexer cluster?
splunk add cluster-config
splunk add cluster-master
splunk edit cluster-config
splunk edit cluster-master
To improve Splunk performance, parallelIngestionPipelines setting can be adjusted on which of the following components in the Splunk architecture? (Select all that apply.)
Indexers
Forwarders
Search head
Cluster master
When adding or decommissioning a member from a Search Head Cluster (SHC), what is the proper order of operations?
1. Delete Splunk Enterprise, if it exists.2. Install and initialize the instance.3. Join the SHC.
1. Install and initialize the instance.2. Delete Splunk Enterprise, if it exists.3. Join the SHC.
1. Initialize cluster rebalance operation.2. Remove master node from cluster.3. Trigger replication.
1. Trigger replication.2. Remove master node from cluster.3. Initialize cluster rebalance operation.
When troubleshooting monitor inputs, which command checks the status of the tailed files?
splunk cmd btool inputs list | tail
splunk cmd btool check inputs layer
curl https://serverhost:8089/services/admin/inputstatus/TailingProcessor:FileStatus
curl https://serverhost:8089/services/admin/inputstatus/TailingProcessor:Tailstatus
Which of the following is a best practice to maximize indexing performance?
Use automatic source typing.
Use the Splunk default settings.
Not use pre-trained source types.
Minimize configuration generality.
Question