Pass the Splunk Splunk Enterprise Certified Architect SPLK-2002 Questions and answers with CertsForce

Viewing page 1 out of 5 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which Splunk internal field can confirm duplicate event issues from failed file monitoring?

Options:

A.

_time


B.

_indextime


C.

_index_latest


D.

latest


Expert Solution
Questions # 2:

Which Splunk component is mandatory when implementing a search head cluster?

Options:

A.

Captain Server


B.

Deployer


C.

Cluster Manager


D.

RAFT Server


Expert Solution
Questions # 3:

A Splunk architect has inherited the Splunk deployment at Buttercup Games and end users are complaining that the events are inconsistently formatted for a web source. Further investigation reveals that not all weblogs flow through the same infrastructure: some of the data goes through heavy forwarders and some of the forwarders are managed by another department.

Which of the following items might be the cause of this issue?

Options:

A.

The search head may have different configurations than the indexers.


B.

The data inputs are not properly configured across all the forwarders.


C.

The indexers may have different configurations than the heavy forwarders.


D.

The forwarders managed by the other department are an older version than the rest.


Expert Solution
Questions # 4:

Which of the following should be included in a deployment plan?

Options:

A.

Business continuity and disaster recovery plans.


B.

Current logging details and data source inventory.


C.

Current and future topology diagrams of the IT environment.


D.

A comprehensive list of stakeholders, either direct or indirect.


Expert Solution
Questions # 5:

What is the expected minimum amount of storage required for data across an indexer cluster with the following input and parameters?

• Raw data = 15 GB per day

• Index files = 35 GB per day

• Replication Factor (RF) = 2

• Search Factor (SF) = 2

Options:

A.

85 GB per day


B.

50 GB per day


C.

100 GB per day


D.

65 GB per day


Expert Solution
Questions # 6:

Which command will permanently decommission a peer node operating in an indexer cluster?

Options:

A.

splunk stop -f


B.

splunk offline -f


C.

splunk offline --enforce-counts


D.

splunk decommission --enforce counts


Expert Solution
Questions # 7:

A monitored log file is changing on the forwarder. However, Splunk searches are not finding any new data that has been added. What are possible causes? (select all that apply)

Options:

A.

An admin ran splunk clean eventdata -index on the indexer.


B.

An admin has removed the Splunk fishbucket on the forwarder.


C.

The last 256 bytes of the monitored file are not changing.


D.

The first 256 bytes of the monitored file are not changing.


Expert Solution
Questions # 8:

Which part of the deployment plan is vital prior to installing Splunk indexer clusters and search head clusters?

Options:

A.

Data source inventory.


B.

Data policy definitions.


C.

Splunk deployment topology.


D.

Education and training plans.


Expert Solution
Questions # 9:

metrics. log is stored in which index?

Options:

A.

main


B.

_telemetry


C.

_internal


D.

_introspection


Expert Solution
Questions # 10:

Which of the following options can improve reliability of syslog delivery to Splunk? (Select all that apply.)

Options:

A.

Use TCP syslog.


B.

Configure UDP inputs on each Splunk indexer to receive data directly.


C.

Use a network load balancer to direct syslog traffic to active backend syslog listeners.


D.

Use one or more syslog servers to persist data with a Universal Forwarder to send the data to Splunk indexers.


Expert Solution
Viewing page 1 out of 5 pages
Viewing questions 1-10 out of questions