New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Splunk Splunk Enterprise Certified Architect SPLK-2002 Questions and answers with CertsForce

Viewing page 6 out of 6 pages
Viewing questions 51-60 out of questions
Questions # 51:

(Which btool command will identify license master configuration errors for a search peer cluster node?)

Options:

A.

splunk cmd btool check —debug


B.

splunk cmd btool server list cluster_license --debug


C.

splunk cmd btool server list clustering —debug


D.

splunk cmd btool server list license --debug


Expert Solution
Questions # 52:

(The performance of a specific search is performing poorly. The search must run over All Time and is expected to have very few results. Analysis shows that the search accesses a very large number of buckets in a large index. What step would most significantly improve the performance of this search?)

Options:

A.

Increase the disk I/O hardware performance.


B.

Increase the number of indexing pipelines.


C.

Set indexed_realtime_use_by_default = true in limits.conf.


D.

Change this to a real-time search using an All Time window.


Expert Solution
Questions # 53:

If .delta replication fails during knowledge bundle replication, what is the fall-back method for Splunk?

Options:

A.

.Restart splunkd.


B.

.delta replication.


C.

.bundle replication.


D.

Restart mongod.


Expert Solution
Questions # 54:

A Splunk environment collecting 10 TB of data per day has 50 indexers and 5 search heads. A single-site indexer cluster will be implemented. Which of the following is a best practice for added data resiliency?

Options:

A.

Set the Replication Factor to 49.


B.

Set the Replication Factor based on allowed indexer failure.


C.

Always use the default Replication Factor of 3.


D.

Set the Replication Factor based on allowed search head failure.


Expert Solution
Questions # 55:

In a distributed environment, knowledge object bundles are replicated from the search head to which location on the search peer(s)?

Options:

A.

SPLUNK_HOME/var/lib/searchpeers


B.

SPLUNK_HOME/var/log/searchpeers


C.

SPLUNK_HOME/var/run/searchpeers


D.

SPLUNK_HOME/var/spool/searchpeers


Expert Solution
Questions # 56:

Users are asking the Splunk administrator to thaw recently-frozen buckets very frequently. What could the Splunk administrator do to reduce the need to thaw buckets?

Options:

A.

Change f rozenTimePeriodlnSecs to a larger value.


B.

Change maxTotalDataSizeMB to a smaller value.


C.

Change maxHotSpanSecs to a larger value.


D.

Change coldToFrozenDir to a different location.


Expert Solution
Questions # 57:

When adding or decommissioning a member from a Search Head Cluster (SHC), what is the proper order of operations?

Options:

A.

1. Delete Splunk Enterprise, if it exists.2. Install and initialize the instance.3. Join the SHC.


B.

1. Install and initialize the instance.2. Delete Splunk Enterprise, if it exists.3. Join the SHC.


C.

1. Initialize cluster rebalance operation.2. Remove master node from cluster.3. Trigger replication.


D.

1. Trigger replication.2. Remove master node from cluster.3. Initialize cluster rebalance operation.


Expert Solution
Questions # 58:

What is the expected minimum amount of storage required for data across an indexer cluster with the following input and parameters?

• Raw data = 15 GB per day

• Index files = 35 GB per day

• Replication Factor (RF) = 2

• Search Factor (SF) = 2

Options:

A.

85 GB per day


B.

50 GB per day


C.

100 GB per day


D.

65 GB per day


Expert Solution
Questions # 59:

(An admin removed and re-added search head cluster (SHC) members as part of patching the operating system. When trying to re-add the first member, a script reverted the SHC member to a previous backup, and the member refuses to join the cluster. What is the best approach to fix the member so that it can re-join?)

Options:

A.

Review splunkd.log for configuration changes preventing the addition of the member.


B.

Delete the [shclustering] stanza in server.conf and restart Splunk.


C.

Force the member add by running splunk edit shcluster-config —force.


D.

Clean the Raft metadata using splunk clean raft.


Expert Solution
Questions # 60:

Which of the following artifacts are included in a Splunk diag file? (Select all that apply.)

Options:

A.

OS settings.


B.

Internal logs.


C.

Customer data.


D.

Configuration files.


Expert Solution
Viewing page 6 out of 6 pages
Viewing questions 51-60 out of questions