Splunk SPLK-2002 Practice Test - Questions Answers, Page 9
List of questions
Related questions
In a distributed environment, knowledge object bundles are replicated from the search head to which location on the search peer(s)?
SPLUNK_HOME/var/lib/searchpeers
SPLUNK_HOME/var/log/searchpeers
SPLUNK_HOME/var/run/searchpeers
SPLUNK_HOME/var/spool/searchpeers
Consider a use case involving firewall data. There is no Splunk-supported Technical Add-On, but the vendor has built one. What are the items that must be evaluated before installing the add-on? (Select all that apply.)
Identify number of scheduled or real-time searches.
Validate if this Technical Add-On enables event data for a data model.
Identify the maximum number of forwarders Technical Add-On can support.
Verify if Technical Add-On needs to be installed onto both a search head or indexer.
When configuring a Splunk indexer cluster, what are the default values for replication and search factor?
replication_factor = 2search_factor = 2
replication_factor = 2search factor = 3
replication_factor = 3search_factor = 2
replication_factor = 3search factor = 3
A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)
The field was extracted as a private knowledge object.
The events are tagged as communicate, but are missing the network tag.
The Typing Queue, which does regular expression replacements, is blocked.
The colleague did not explicitly use the field in the search and the search was set to Fast Mode.
Which two sections can be expanded using the Search Job Inspector?
Execution costs.
Saved search history.
Search job properties.
Optimization suggestions.
What is the default log size for Splunk internal logs?
10MB
20 MB
25MB
30MB
What is a Splunk Job? (Select all that apply.)
A user-defined Splunk capability.
Searches that are subjected to some usage quota.
A search process kicked off via a report or an alert.
A child OS process manifested from the splunkd process.
When Splunk is installed, where are the internal indexes stored by default?
SPLUNK_HOME/bin
SPLUNK_HOME/var/lib
SPLUNK_HOME/var/run
SPLUNK_HOME/etc/system/default
Which of the following options can improve reliability of syslog delivery to Splunk? (Select all that apply.)
Use TCP syslog.
Configure UDP inputs on each Splunk indexer to receive data directly.
Use a network load balancer to direct syslog traffic to active backend syslog listeners.
Use one or more syslog servers to persist data with a Universal Forwarder to send the data to Splunk indexers.
What is the logical first step when starting a deployment plan?
Inventory the currently deployed logging infrastructure.
Determine what apps and use cases will be implemented.
Gather statistics on the expected adoption of Splunk for sizing.
Collect the initial requirements for the deployment from all stakeholders.
Question