Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Splunk Splunk Enterprise Certified Architect SPLK-2002 Questions and answers with CertsForce

Viewing page 2 out of 6 pages
Viewing questions 11-20 out of questions
Questions # 11:

A single-site indexer cluster has a replication factor of 3, and a search factor of 2. What is true about this cluster?

Options:

A.

The cluster will ensure there are at least two copies of each bucket, and at least three copies of searchable metadata.


B.

The cluster will ensure there are at most three copies of each bucket, and at most two copies of searchable metadata.


C.

The cluster will ensure only two search heads are allowed to access the bucket at the same time.


D.

The cluster will ensure there are at least three copies of each bucket, and at least two copies of searchable metadata.


Expert Solution
Questions # 12:

When troubleshooting a situation where some files within a directory are not being indexed, the ignored files are discovered to have long headers. What is the first thing that should be added to inputs.conf?

Options:

A.

Decrease the value of initCrcLength.


B.

Add a crcSalt= attribute.


C.

Increase the value of initCrcLength.


D.

Add a crcSalt= attribute.


Expert Solution
Questions # 13:

A Splunk architect has inherited the Splunk deployment at Buttercup Games and end users are complaining that the events are inconsistently formatted for a web source. Further investigation reveals that not all weblogs flow through the same infrastructure: some of the data goes through heavy forwarders and some of the forwarders are managed by another department.

Which of the following items might be the cause of this issue?

Options:

A.

The search head may have different configurations than the indexers.


B.

The data inputs are not properly configured across all the forwarders.


C.

The indexers may have different configurations than the heavy forwarders.


D.

The forwarders managed by the other department are an older version than the rest.


Expert Solution
Questions # 14:

Which CLI command converts a Splunk instance to a license slave?

Options:

A.

splunk add licenses


B.

splunk list licenser-slaves


C.

splunk edit licenser-localslave


D.

splunk list licenser-localslave


Expert Solution
Questions # 15:

A customer has a four site indexer cluster. The customer has requirements to store five copies of searchable data, with one searchable copy of data at the origin site, and one searchable copy at the disaster recovery site (site4).

Which configuration meets these requirements?

Options:

A.

site_replication_factor = origin:2, site4:l, total:3


B.

site_replication_factor = origin:l, site4:l, total:5


C.

site_search_factor = origin:2, site4:l, total:3


D.

site search factor = origin:1, site4:l, total:5


Expert Solution
Questions # 16:

What is the logical first step when starting a deployment plan?

Options:

A.

Inventory the currently deployed logging infrastructure.


B.

Determine what apps and use cases will be implemented.


C.

Gather statistics on the expected adoption of Splunk for sizing.


D.

Collect the initial requirements for the deployment from all stakeholders.


Expert Solution
Questions # 17:

When implementing KV Store Collections in a search head cluster, which of the following considerations is true?

Options:

A.

The KV Store Primary coordinates with the search head cluster captain when collection content changes.


B.

The search head cluster captain is also the KV Store Primary when collection content changes.


C.

The KV Store Collection will not allow for changes to content if there are more than 50 search heads in the cluster.


D.

Each search head in the cluster independently updates its KV store collection when collection content changes.


Expert Solution
Questions # 18:

At which default interval does metrics.log generate a periodic report regarding license utilization?

Options:

A.

10 seconds


B.

30 seconds


C.

60 seconds


D.

300 seconds


Expert Solution
Questions # 19:

(What is a recommended way to improve search performance?)

Options:

A.

Use the shortest query possible.


B.

Filter as much as possible in the initial search.


C.

Use non-streaming commands as early as possible.


D.

Leverage the not expression to limit returned results.


Expert Solution
Questions # 20:

Which instance can not share functionality with the deployer?

Options:

A.

Search head cluster member


B.

License master


C.

Master node


D.

Monitoring Console (MC)


Expert Solution
Viewing page 2 out of 6 pages
Viewing questions 11-20 out of questions