A single-site indexer cluster has a replication factor of 3, and a search factor of 2. What is true about this cluster?
(If the maxDataSize attribute is set to auto_high_volume in indexes.conf on a 64-bit operating system, what is the maximum hot bucket size?)
A customer has installed a 500GB Enterprise license. They also purchased and installed a 300GB, no enforcement license on the same license master. How much data can the customer ingest before the search is locked out?
The master node distributes configuration bundles to peer nodes. Which directory peer nodes receive the bundles?
Which of the following statements describe licensing in a clustered Splunk deployment? (Select all that apply.)
Which of the following is a valid use case that a search head cluster addresses?
Other than high availability, which of the following is a benefit of search head clustering?
(A customer has converted a CSV lookup to a KV Store lookup. What must be done to make it available for an automatic lookup?)
A Splunk architect has inherited the Splunk deployment at Buttercup Games and end users are complaining that the events are inconsistently formatted for a web source. Further investigation reveals that not all weblogs flow through the same infrastructure: some of the data goes through heavy forwarders and some of the forwarders are managed by another department.
Which of the following items might be the cause of this issue?
Which server.conf attribute should be added to the master node's server.conf file when decommissioning a site in an indexer cluster?
Which of the following clarification steps should be taken if apps are not appearing on a deployment client? (Select all that apply.)
(A customer has an environment with a Search Head Cluster and an indexer cluster. They are troubleshooting license usage data, including indexed volume in bytes per pool, index, host, sourcetype, and source. Where should the license_usage.log file be retrieved from in this environment?)
A three-node search head cluster is skipping a large number of searches across time. What should be done to increase scheduled search capacity on the search head cluster?
Which of the following are client filters available in serverclass.conf? (Select all that apply.)
Which of the following is true regarding Splunk Enterprise's performance? (Select all that apply.)
When troubleshooting a situation where some files within a directory are not being indexed, the ignored files are discovered to have long headers. What is the first thing that should be added to inputs.conf?
A search head cluster with a KV store collection can be updated from where in the KV store collection?
Which part of the deployment plan is vital prior to installing Splunk indexer clusters and search head clusters?
Which search head cluster component is responsible for pushing knowledge bundles to search peers, replicating configuration changes to search head cluster members, and scheduling jobs across the search head cluster?
(Where can files be placed in a configuration bundle on a search peer that will persist after a new configuration bundle has been deployed?)
Which of the following statements describe a Search Head Cluster (SHC) captain? (Select all that apply.)
What information is needed about the current environment before deploying Splunk? (select all that apply)
When configuring a Splunk indexer cluster, what are the default values for replication and search factor?
A customer currently has many deployment clients being managed by a single, dedicated deployment server. The customer plans to double the number of clients.
What could be done to minimize performance issues?
An indexer cluster is being designed with the following characteristics:
• 10 search peers
• Replication Factor (RF): 4
• Search Factor (SF): 3
• No SmartStore usage
How many search peers can fail before data becomes unsearchable?
A customer plans to ingest 600 GB of data per day into Splunk. They will have six concurrent users, and they also want high data availability and high search performance. The customer is concerned about cost and wants to spend the minimum amount on the hardware for Splunk. How many indexers are recommended for this deployment?
Of the following types of files within an index bucket, which file type may consume the most disk?
A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)
On search head cluster members, where in $splunk_home does the Splunk Deployer deploy app content by default?
Stakeholders have identified high availability for searchable data as their top priority. Which of the following best addresses this requirement?
Configurations from the deployer are merged into which location on the search head cluster member?
(How can a Splunk admin control the logging level for a specific search to get further debug information?)
Which of the following use cases would be made possible by multi-site clustering? (select all that apply)
By default, what happens to configurations in the local folder of each Splunk app when it is deployed to a search head cluster?
Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)
A Splunk environment collecting 10 TB of data per day has 50 indexers and 5 search heads. A single-site indexer cluster will be implemented. Which of the following is a best practice for added data resiliency?
Before users can use a KV store, an admin must create a collection. Where is a collection is defined?
(Which command is used to initially add a search head to a single-site indexer cluster?)
Which command should be run to re-sync a stale KV Store member in a search head cluster?
Which command will permanently decommission a peer node operating in an indexer cluster?
(Based on the data sizing and retention parameters listed below, which of the following will correctly calculate the index storage required?)
• Daily rate = 20 GB / day
• Compress factor = 0.5
• Retention period = 30 days
• Padding = 100 GB
A multi-site indexer cluster can be configured using which of the following? (Select all that apply.)
Users are asking the Splunk administrator to thaw recently-frozen buckets very frequently. What could the Splunk administrator do to reduce the need to thaw buckets?
In the deployment planning process, when should a person identify who gets to see network data?
Splunk Enterprise Certified Architect | SPLK-2002 Questions Answers | SPLK-2002 Test Prep | Splunk Enterprise Certified Architect Questions PDF | SPLK-2002 Online Exam | SPLK-2002 Practice Test | SPLK-2002 PDF | SPLK-2002 Test Questions | SPLK-2002 Study Material | SPLK-2002 Exam Preparation | SPLK-2002 Valid Dumps | SPLK-2002 Real Questions | Splunk Enterprise Certified Architect SPLK-2002 Exam Questions