New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Splunk Splunk Enterprise Certified Architect SPLK-2002 Questions and answers with CertsForce

Viewing page 1 out of 6 pages
Viewing questions 1-10 out of questions
Questions # 1:

What types of files exist in a bucket within a clustered index? (select all that apply)

Options:

A.

Inside a replicated bucket, there is only rawdata.


B.

Inside a searchable bucket, there is only tsidx.


C.

Inside a searchable bucket, there is tsidx and rawdata.


D.

Inside a replicated bucket, there is both tsidx and rawdata.


Expert Solution
Questions # 2:

A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)

Options:

A.

The field was extracted as a private knowledge object.


B.

The events are tagged as communicate, but are missing the network tag.


C.

The Typing Queue, which does regular expression replacements, is blocked.


D.

The colleague did not explicitly use the field in the search and the search was set to Fast Mode.


Expert Solution
Questions # 3:

Which index-time props.conf attributes impact indexing performance? (Select all that apply.)

Options:

A.

REPORT


B.

LINE_BREAKER


C.

ANNOTATE_PUNCT


D.

SHOULD_LINEMERGE


Expert Solution
Questions # 4:

Which component in the splunkd.log will log information related to bad event breaking?

Options:

A.

Audittrail


B.

EventBreaking


C.

IndexingPipeline


D.

AggregatorMiningProcessor


Expert Solution
Questions # 5:

Which of the following is a problem that could be investigated using the Search Job Inspector?

Options:

A.

Error messages are appearing underneath the search bar in Splunk Web.


B.

Dashboard panels are showing "Waiting for queued job to start" on page load.


C.

Different users are seeing different extracted fields from the same search.


D.

Events are not being sorted in reverse chronological order.


Expert Solution
Questions # 6:

A monitored log file is changing on the forwarder. However, Splunk searches are not finding any new data that has been added. What are possible causes? (select all that apply)

Options:

A.

An admin ran splunk clean eventdata -index on the indexer.


B.

An admin has removed the Splunk fishbucket on the forwarder.


C.

The last 256 bytes of the monitored file are not changing.


D.

The first 256 bytes of the monitored file are not changing.


Expert Solution
Questions # 7:

How can internal logging levels in a Splunk environment be changed to troubleshoot an issue? (select all that apply)

Options:

A.

Use the Monitoring Console (MC).


B.

Use Splunk command line.


C.

Use Splunk Web.


D.

Edit log-local. cfg.


Expert Solution
Questions # 8:

Which of the following options can improve reliability of syslog delivery to Splunk? (Select all that apply.)

Options:

A.

Use TCP syslog.


B.

Configure UDP inputs on each Splunk indexer to receive data directly.


C.

Use a network load balancer to direct syslog traffic to active backend syslog listeners.


D.

Use one or more syslog servers to persist data with a Universal Forwarder to send the data to Splunk indexers.


Expert Solution
Questions # 9:

New data has been added to a monitor input file. However, searches only show older data.

Which splunkd. log channel would help troubleshoot this issue?

Options:

A.

Modularlnputs


B.

TailingProcessor


C.

ChunkedLBProcessor


D.

ArchiveProcessor


Expert Solution
Questions # 10:

Which instance can not share functionality with the deployer?

Options:

A.

Search head cluster member


B.

License master


C.

Master node


D.

Monitoring Console (MC)


Expert Solution
Viewing page 1 out of 6 pages
Viewing questions 1-10 out of questions