Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Splunk Splunk Enterprise Certified Architect SPLK-2002 Questions and answers with CertsForce

Viewing page 6 out of 6 pages
Viewing questions 51-60 out of questions
Questions # 51:

(Which command is used to initially add a search head to a single-site indexer cluster?)

Options:

A.

splunk edit cluster-config -mode searchhead -manager_uri https://10.0.0.1:8089 -secret changeme


B.

splunk edit cluster-config -mode peer -manager_uri https://10.0.0.1:8089 -secret changeme


C.

splunk add cluster-manager -manager_uri https://10.0.0.1:8089 -secret changeme


D.

splunk add cluster-manager -mode searchhead -manager_uri https://10.0.0.1:8089 -secret changeme


Expert Solution
Questions # 52:

(What is the best way to configure and manage receiving ports for clustered indexers?)

Options:

A.

Use Splunk Web to create the receiving port on each peer node.


B.

Define the receiving port in /etc/deployment-apps/cluster-app/local/inputs.conf and deploy it to the peer nodes.


C.

Run the splunk enable listen command on each peer node.


D.

Define the receiving port in /etc/manager-apps/_cluster/local/inputs.conf and push it to the peer nodes.


Expert Solution
Questions # 53:

(How is the search log accessed for a completed search job?)

Options:

A.

Search for: index=_internal sourcetype=search.


B.

Select Settings > Searches, reports, and alerts, then from the Actions column, select View Search Log.


C.

From the Activity menu, select Show Search Log.


D.

From the Job menu, select Inspect Job, then click the search.log link.


Expert Solution
Questions # 54:

Which of the following is true regarding the migration of an index cluster from single-site to multi-site?

Options:

A.

Multi-site policies will apply to all data in the indexer cluster.


B.

All peer nodes must be running the same version of Splunk.


C.

Existing single-site attributes must be removed.


D.

Single-site buckets cannot be converted to multi-site buckets.


Expert Solution
Questions # 55:

How does the average run time of all searches relate to the available CPU cores on the indexers?

Options:

A.

Average run time is independent of the number of CPU cores on the indexers.


B.

Average run time decreases as the number of CPU cores on the indexers decreases.


C.

Average run time increases as the number of CPU cores on the indexers decreases.


D.

Average run time increases as the number of CPU cores on the indexers increases.


Expert Solution
Questions # 56:

Which Splunk log file would be the least helpful in troubleshooting a crash?

Options:

A.

splunk_instrumentation.log


B.

splunkd_stderr.log


C.

crash-2022-05-13-ll:42:57.1og


D.

splunkd.log


Expert Solution
Questions # 57:

(Which of the following has no impact on search performance?)

Options:

A.

Decreasing the phone home interval for deployment clients.


B.

Increasing the number of indexers in the indexer tier.


C.

Allocating compute and memory resources with Workload Management.


D.

Increasing the number of search heads in a Search Head Cluster.


Expert Solution
Questions # 58:

To expand the search head cluster by adding a new member, node2, what first step is required?

Options:

A.

splunk bootstrap shcluster-config -mgmt_uri https://node2:8089 -replication_port 9200 -secret supersecretkey


B.

splunk init shcluster-config -master_uri https://node2:8089 -replication_port 9200 -secret supersecretkey


C.

splunk init shcluster-config -mgmt_uri https://node2:8089 -replication_port 9200 -secret supersecretkey


D.

splunk add shcluster-member -new_member_uri https://node2:8089 -replication_port 9200 -secret supersecretkey


Expert Solution
Questions # 59:

How many cluster managers are required for a multisite indexer cluster?

Options:

A.

Two for the entire cluster.


B.

One for each site.


C.

One for the entire cluster.


D.

Two for each site.


Expert Solution
Questions # 60:

Which of the following is a best practice to maximize indexing performance?

Options:

A.

Use automatic source typing.


B.

Use the Splunk default settings.


C.

Not use pre-trained source types.


D.

Minimize configuration generality.


Expert Solution
Viewing page 6 out of 6 pages
Viewing questions 51-60 out of questions