Pass the Splunk Splunk Enterprise Certified Architect SPLK-2002 Questions and answers with CertsForce

Viewing page 5 out of 5 pages
Viewing questions 41-50 out of questions
Questions # 41:

Which server.conf attribute should be added to the master node's server.conf file when decommissioning a site in an indexer cluster?

Options:

A.

site_mappings


B.

available_sites


C.

site_search_factor


D.

site_replication_factor


Expert Solution
Questions # 42:

When converting from a single-site to a multi-site cluster, what happens to existing single-site clustered buckets?

Options:

A.

They will continue to replicate within the origin site and age out based on existing policies.


B.

They will maintain replication as required according to the single-site policies, but never age out.


C.

They will be replicated across all peers in the multi-site cluster and age out based on existing policies.


D.

They will stop replicating within the single-site and remain on the indexer they reside on and age out according to existing policies.


Expert Solution
Questions # 43:

Following Splunk recommendations, where could the Monitoring Console (MC) be installed in a distributed deployment with an indexer cluster, a search head cluster, and 1000 forwarders?

Options:

A.

On a search peer in the cluster.


B.

On the deployment server.


C.

On the search head cluster deployer.


D.

On a search head in the cluster.


Expert Solution
Questions # 44:

Which of the following is a way to exclude search artifacts when creating a diag?

Options:

A.

SPLUNK_HOME/bin/splunk diag --exclude


B.

SPLUNK_HOME/bin/splunk diag --debug --refresh


C.

SPLUNK_HOME/bin/splunk diag --disable=dispatch


D.

SPLUNK_HOME/bin/splunk diag --filter-searchstrings


Expert Solution
Questions # 45:

Which Splunk log file would be the least helpful in troubleshooting a crash?

Options:

A.

splunk_instrumentation.log


B.

splunkd_stderr.log


C.

crash-2022-05-13-ll:42:57.1og


D.

splunkd.log


Expert Solution
Questions # 46:

Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)

Options:

A.

Install Enterprise Security on the deployer.


B.

Install Enterprise Security on a staging instance.


C.

Copy the Enterprise Security configurations to the deployer.


D.

Use the deployer to deploy Enterprise Security to the cluster members.


Expert Solution
Questions # 47:

What does the deployer do in a Search Head Cluster (SHC)? (Select all that apply.)

Options:

A.

Distributes apps to SHC members.


B.

Bootstraps a clean Splunk install for a SHC.


C.

Distributes non-search-related and manual configuration file changes.


D.

Distributes runtime knowledge object changes made by users across the SHC.


Expert Solution
Questions # 48:

Which Splunk internal index contains license-related events?

Options:

A.

_audit


B.

_license


C.

_internal


D.

_introspection


Expert Solution
Viewing page 5 out of 5 pages
Viewing questions 41-50 out of questions