Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Splunk Splunk Enterprise Certified Architect SPLK-2002 Questions and answers with CertsForce

Viewing page 3 out of 6 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which of the following is true for indexer cluster knowledge bundles?

Options:

A.

Only app-name/local is pushed.


B.

app-name/default and app-name/local are merged before pushing.


C.

Only app-name/default is pushed.


D.

app-name/default and app-name/local are pushed without change.


Expert Solution
Questions # 22:

metrics. log is stored in which index?

Options:

A.

main


B.

_telemetry


C.

_internal


D.

_introspection


Expert Solution
Questions # 23:

Before users can use a KV store, an admin must create a collection. Where is a collection is defined?

Options:

A.

kvstore.conf


B.

collection.conf


C.

collections.conf


D.

kvcollections.conf


Expert Solution
Questions # 24:

What does setting site=site0 on all Search Head Cluster members do in a multi-site indexer cluster?

Options:

A.

Disables search site affinity.


B.

Sets all members to dynamic captaincy.


C.

Enables multisite search artifact replication.


D.

Enables automatic search site affinity discovery.


Expert Solution
Questions # 25:

When Splunk indexes data in a non-clustered environment, what kind of files does it create by default?

Options:

A.

Index and .tsidx files.


B.

Rawdata and index files.


C.

Compressed and .tsidx files.


D.

Compressed and meta data files.


Expert Solution
Questions # 26:

(Based on the data sizing and retention parameters listed below, which of the following will correctly calculate the index storage required?)

• Daily rate = 20 GB / day

• Compress factor = 0.5

• Retention period = 30 days

• Padding = 100 GB

Options:

A.

(20 * 30 + 100) * 0.5 = 350 GB


B.

20 / 0.5 * 30 + 100 = 1300 GB


C.

20 * 0.5 * 30 + 100 = 400 GB


D.

20 * 30 + 100 = 700 GB


Expert Solution
Questions # 27:

In splunkd. log events written to the _internal index, which field identifies the specific log channel?

Options:

A.

component


B.

source


C.

sourcetype


D.

channel


Expert Solution
Questions # 28:

(A high-volume source and a low-volume source feed into the same index. Which of the following items best describe the impact of this design choice?)

Options:

A.

Low volume data will improve the compression factor of the high volume data.


B.

Search speed on low volume data will be slower than necessary.


C.

Low volume data may move out of the index based on volume rather than age.


D.

High volume data is optimized by the presence of low volume data.


Expert Solution
Questions # 29:

What information is written to the __introspection log file?

Options:

A.

File monitor input configurations.


B.

File monitor checkpoint offset.


C.

User activities and knowledge objects.


D.

KV store performance.


Expert Solution
Questions # 30:

Which of the following options can improve reliability of syslog delivery to Splunk? (Select all that apply.)

Options:

A.

Use TCP syslog.


B.

Configure UDP inputs on each Splunk indexer to receive data directly.


C.

Use a network load balancer to direct syslog traffic to active backend syslog listeners.


D.

Use one or more syslog servers to persist data with a Universal Forwarder to send the data to Splunk indexers.


Expert Solution
Viewing page 3 out of 6 pages
Viewing questions 21-30 out of questions