New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Splunk Splunk Enterprise Certified Architect SPLK-2002 Questions and answers with CertsForce

Viewing page 3 out of 6 pages
Viewing questions 21-30 out of questions
Questions # 21:

When should multiple search pipelines be enabled?

Options:

A.

Only if disk IOPS is at 800 or better.


B.

Only if there are fewer than twelve concurrent users.


C.

Only if running Splunk Enterprise version 6.6 or later.


D.

Only if CPU and memory resources are significantly under-utilized.


Expert Solution
Questions # 22:

What is the default log size for Splunk internal logs?

Options:

A.

10MB


B.

20 MB


C.

25MB


D.

30MB


Expert Solution
Questions # 23:

Which of the following clarification steps should be taken if apps are not appearing on a deployment client? (Select all that apply.)

Options:

A.

Check serverclass.conf of the deployment server.


B.

Check deploymentclient.conf of the deployment client.


C.

Check the content of SPLUNK_HOME/etc/apps of the deployment server.


D.

Search for relevant events in splunkd.log of the deployment server.


Expert Solution
Questions # 24:

A three-node search head cluster is skipping a large number of searches across time. What should be done to increase scheduled search capacity on the search head cluster?

Options:

A.

Create a job server on the cluster.


B.

Add another search head to the cluster.


C.

server.conf captain_is_adhoc_searchhead = true.


D.

Change limits.conf value for max_searches_per_cpu to a higher value.


Expert Solution
Questions # 25:

Which of the following is a best practice to maximize indexing performance?

Options:

A.

Use automatic source typing.


B.

Use the Splunk default settings.


C.

Not use pre-trained source types.


D.

Minimize configuration generality.


Expert Solution
Questions # 26:

(Which Splunk component allows viewing of the LISPY to assist in debugging Splunk searches?)

Options:

A.

dbinspect


B.

Monitoring Console


C.

walklex


D.

Search Job Inspector


Expert Solution
Questions # 27:

Indexing is slow and real-time search results are delayed in a Splunk environment with two indexers and one search head. There is ample CPU and memory available on the indexers. Which of the following is most likely to improve indexing performance?

Options:

A.

Increase the maximum number of hot buckets in indexes.conf


B.

Increase the number of parallel ingestion pipelines in server.conf


C.

Decrease the maximum size of the search pipelines in limits.conf


D.

Decrease the maximum concurrent scheduled searches in limits.conf


Expert Solution
Questions # 28:

Which two sections can be expanded using the Search Job Inspector?

Options:

A.

Execution costs.


B.

Saved search history.


C.

Search job properties.


D.

Optimization suggestions.


Expert Solution
Questions # 29:

Where in the Job Inspector can details be found to help determine where performance is affected?

Options:

A.

Search Job Properties > runDuration


B.

Search Job Properties > runtime


C.

Job Details Dashboard > Total Events Matched


D.

Execution Costs > Components


Expert Solution
Questions # 30:

(How is the search log accessed for a completed search job?)

Options:

A.

Search for: index=_internal sourcetype=search.


B.

Select Settings > Searches, reports, and alerts, then from the Actions column, select View Search Log.


C.

From the Activity menu, select Show Search Log.


D.

From the Job menu, select Inspect Job, then click the search.log link.


Expert Solution
Viewing page 3 out of 6 pages
Viewing questions 21-30 out of questions