Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Splunk Splunk Enterprise Certified Architect SPLK-2002 Questions and answers with CertsForce

Viewing page 1 out of 6 pages
Viewing questions 1-10 out of questions
Questions # 1:

A customer is migrating 500 Universal Forwarders from an old deployment server to a new deployment server, with a different DNS name. The new deployment server is configured and running.

The old deployment server deployed an app containing an updated deploymentclient.conf file to all forwarders, pointing them to the new deployment server. The app was successfully deployed to all 500 forwarders.

Why would all of the forwarders still be phoning home to the old deployment server?

Options:

A.

There is a version mismatch between the forwarders and the new deployment server.


B.

The new deployment server is not accepting connections from the forwarders.


C.

The forwarders are configured to use the old deployment server in $SPLUNK_HOME/etc/system/local.


D.

The pass4SymmKey is the same on the new deployment server and the forwarders.


Expert Solution
Questions # 2:

In the deployment planning process, when should a person identify who gets to see network data?

Options:

A.

Deployment schedule


B.

Topology diagramming


C.

Data source inventory


D.

Data policy definition


Expert Solution
Questions # 3:

As of Splunk 9.0, which index records changes to . conf files?

Options:

A.

_configtracker


B.

_introspection


C.

_internal


D.

_audit


Expert Solution
Questions # 4:

Which Splunk internal index contains license-related events?

Options:

A.

_audit


B.

_license


C.

_internal


D.

_introspection


Expert Solution
Questions # 5:

Which of the following Splunk deployments has the recommended minimum components for a high-availability search head cluster?

Options:

A.

2 search heads, 1 deployer, 2 indexers


B.

3 search heads, 1 deployer, 3 indexers


C.

1 search head, 1 deployer, 3 indexers


D.

2 search heads, 1 deployer, 3 indexers


Expert Solution
Questions # 6:

Configurations from the deployer are merged into which location on the search head cluster member?

Options:

A.

SPLUNK_HOME/etc/system/local


B.

SPLUNK_HOME/etc/apps/APP_HOME/local


C.

SPLUNK_HOME/etc/apps/search/default


D.

SPLUNK_HOME/etc/apps/APP_HOME/default


Expert Solution
Questions # 7:

(If a license peer cannot communicate to a license manager for 72 hours or more, what will happen?)

Options:

A.

The license peer is placed in violation, and a warning is generated.


B.

A license warning is generated, and there is no impact to the license peer.


C.

What happens depends on license type.


D.

The license peer is placed in violation, and search is blocked.


Expert Solution
Questions # 8:

(A customer creates a saved search that runs on a specific interval. Which internal Splunk log should be viewed to determine if the search ran recently?)

Options:

A.

metrics.log


B.

kvstore.log


C.

scheduler.log


D.

btool.log


Expert Solution
Questions # 9:

(Which btool command will identify license master configuration errors for a search peer cluster node?)

Options:

A.

splunk cmd btool check —debug


B.

splunk cmd btool server list cluster_license --debug


C.

splunk cmd btool server list clustering —debug


D.

splunk cmd btool server list license --debug


Expert Solution
Questions # 10:

Which index-time props.conf attributes impact indexing performance? (Select all that apply.)

Options:

A.

REPORT


B.

LINE_BREAKER


C.

ANNOTATE_PUNCT


D.

SHOULD_LINEMERGE


Expert Solution
Viewing page 1 out of 6 pages
Viewing questions 1-10 out of questions