(Which indexes.conf attribute would prevent an index from participating in an indexer cluster?)
(A customer creates a saved search that runs on a specific interval. Which internal Splunk log should be viewed to determine if the search ran recently?)
(On which Splunk components does the Splunk App for Enterprise Security place the most load?)
What is the algorithm used to determine captaincy in a Splunk search head cluster?
On search head cluster members, where in $splunk_home does the Splunk Deployer deploy app content by default?
In search head clustering, which of the following methods can you use to transfer captaincy to a different member? (Select all that apply.)
Which of the following is true regarding Splunk Enterprise's performance? (Select all that apply.)
(A customer wishes to keep costs to a minimum, while still implementing Search Head Clustering (SHC). What are the minimum supported architecture standards?)
(What is the expected performance reduction when architecting Splunk in a virtualized environment instead of a physical environment?)
At which default interval does metrics.log generate a periodic report regarding license utilization?
Which Splunk tool offers a health check for administrators to evaluate the health of their Splunk deployment?
If there is a deployment server with many clients and one deployment client is not updating apps, which of the following should be done first?
Which component in the splunkd.log will log information related to bad event breaking?
A Splunk instance has the following settings in SPLUNK_HOME/etc/system/local/server.conf:
[clustering]
mode = master
replication_factor = 2
pass4SymmKey = password123
Which of the following statements describe this Splunk instance? (Select all that apply.)
How does IT Service Intelligence (ITSI) impact the planning of a Splunk deployment?
Which of the following describe migration from single-site to multisite index replication?
Before users can use a KV store, an admin must create a collection. Where is a collection is defined?
(What is the best way to configure and manage receiving ports for clustered indexers?)
What is needed to ensure that high-velocity sources will not have forwarding delays to the indexers?
A three-node search head cluster is skipping a large number of searches across time. What should be done to increase scheduled search capacity on the search head cluster?
Because Splunk indexing is read/write intensive, it is important to select the appropriate disk storage solution for each deployment. Which of the following statements is accurate about disk storage?
A customer plans to ingest 600 GB of data per day into Splunk. They will have six concurrent users, and they also want high data availability and high search performance. The customer is concerned about cost and wants to spend the minimum amount on the hardware for Splunk. How many indexers are recommended for this deployment?
To reduce the captain's work load in a search head cluster, what setting will prevent scheduled searches from running on the captain?
A monitored log file is changing on the forwarder. However, Splunk searches are not finding any new data that has been added. What are possible causes? (select all that apply)
Which of the following is true regarding the migration of an index cluster from single-site to multi-site?
Splunk configuration parameter settings can differ between multiple .conf files of the same name contained within different apps. Which of the following directories has the highest precedence?
The master node distributes configuration bundles to peer nodes. Which directory peer nodes receive the bundles?
Which of the following configuration attributes must be set in server, conf on the cluster manager in a single-site indexer cluster?
(Which of the following is a valid way to determine if a new bundle push will trigger a rolling restart?)
(A customer has a Splunk Enterprise deployment and wants to collect data from universal forwarders. What is the best step to secure log traffic?)
Which command should be run to re-sync a stale KV Store member in a search head cluster?
A customer is migrating 500 Universal Forwarders from an old deployment server to a new deployment server, with a different DNS name. The new deployment server is configured and running.
The old deployment server deployed an app containing an updated deploymentclient.conf file to all forwarders, pointing them to the new deployment server. The app was successfully deployed to all 500 forwarders.
Why would all of the forwarders still be phoning home to the old deployment server?
Which of the following options can improve reliability of syslog delivery to Splunk? (Select all that apply.)
Following Splunk recommendations, where could the Monitoring Console (MC) be installed in a distributed deployment with an indexer cluster, a search head cluster, and 1000 forwarders?
(Which Splunk component allows viewing of the LISPY to assist in debugging Splunk searches?)
What does setting site=site0 on all Search Head Cluster members do in a multi-site indexer cluster?
Which of the following security options must be explicitly configured (i.e. which options are not enabled by default)?
(Which btool command will identify license master configuration errors for a search peer cluster node?)
Several critical searches that were functioning correctly yesterday are not finding a lookup table today. Which log file would be the best place to start troubleshooting?
Other than high availability, which of the following is a benefit of search head clustering?
Which of the following use cases would be made possible by multi-site clustering? (select all that apply)
(A high-volume source and a low-volume source feed into the same index. Which of the following items best describe the impact of this design choice?)
When Splunk indexes data in a non-clustered environment, what kind of files does it create by default?
Splunk Enterprise Certified Architect | SPLK-2002 Questions Answers | SPLK-2002 Test Prep | Splunk Enterprise Certified Architect Questions PDF | SPLK-2002 Online Exam | SPLK-2002 Practice Test | SPLK-2002 PDF | SPLK-2002 Test Questions | SPLK-2002 Study Material | SPLK-2002 Exam Preparation | SPLK-2002 Valid Dumps | SPLK-2002 Real Questions | Splunk Enterprise Certified Architect SPLK-2002 Exam Questions