Pass the Splunk Splunk Core Certified Consultant SPLK-3003 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

Data can be onboarded using apps, Splunk Web, or the CLI.

Which is the PS preferred method?

Options:

A.

Create UDP input port 9997 on a UF.


B.

Use the add data wizard in Splunk Web.


C.

Use the inputs.conf file.


D.

Use a scripted input to monitor a log file.


Expert Solution
Questions # 2:

A customer has been using Splunk for one year, utilizing a single/all-in-one instance. This single Splunk server is now struggling to cope with the daily ingest rate. Also, Splunk has become a vital system in day-to-day operations making high availability a consideration for the Splunk service. The customer is unsure how to design the new environment topology in order to provide this.

Which resource would help the customer gather the requirements for their new architecture?

Options:

A.

Direct the customer to the docs.splunk.com and tell them that all the information to help them select the right design is documented there.


B.

Ask the customer to engage with the sales team immediately as they probably need a larger license.


C.

Refer the customer to answers.splunk.com as someone else has probably already designed a system that meets their requirements.


D.

Refer the customer to the Splunk Validated Architectures document in order to guide them through which approved architectures could meet their requirements.


Expert Solution
Questions # 3:

A customer has a number of inefficient regex replacement transforms being applied. When under heavy load the indexers are struggling to maintain the expected indexing rate. In a worst-case scenario, which queue(s) would be expected to fill up?

Options:

A.

Typing, merging, parsing, input


B.

Parsing


C.

Typing


D.

Indexing, typing, merging, parsing, input


Expert Solution
Questions # 4:

A [script://] input sends data to a Splunk forwarder using which method?

Options:

A.

UDP stream


B.

TCP stream


C.

Temporary file


D.

STDOUT/STDERR


Expert Solution
Questions # 5:

A new single-site three indexer cluster is being stood up with replication_factor:2, search_factor:2. At which step would the Indexer Cluster be classed as ‘Indexing Ready’ and be able to ingest new data?

Step 1: Install and configure Cluster Master (CM)/Master Node with base clustering stanza settings, restarting CM.

Step 2: Configure a base app in etc/master-apps on the CM to enable a splunktcp input on port 9997 and deploy index creation configurations.

Step 3: Install and configure Indexer 1 so that once restarted, it contacts the CM, download the latest config bundle.

Step 4: Indexer 1 restarts and has successfully joined the cluster.

Step 5: Install and configure Indexer 2 so that once restarted, it contacts the CM, downloads the latest config bundle

Step 6: Indexer 2 restarts and has successfully joined the cluster.

Step 7: Install and configure Indexer 3 so that once restarted, it contacts the CM, downloads the latest config bundle.

Step 8: Indexer 3 restarts and has successfully joined the cluster.

Options:

A.

Step 2


B.

Step 4


C.

Step 6


D.

Step 8


Expert Solution
Questions # 6:

A customer has a network device that transmits logs directly with UDP or TCP over SSL. Using PS best practices, which ingestion method should be used?

Options:

A.

Open a TCP port with SSL on a heavy forwarder to parse and transmit the data to the indexing tier.


B.

Open a UDP port on a universal forwarder to parse and transmit the data to the indexing tier.


C.

Use a syslog server to aggregate the data to files and use a heavy forwarder to read and transmit the data to the indexing tier.


D.

Use a syslog server to aggregate the data to files and use a universal forwarder to read and transmit the data to the indexing tier.


Expert Solution
Questions # 7:

Which of the following server roles should be configured for a host which indexes its internal logs locally?

Options:

A.

Cluster master


B.

Indexer


C.

Monitoring Console (MC)


D.

Search head


Expert Solution
Questions # 8:

How could a role in which all users must specify an index=clause in all searches be configured?

Options:

A.

Set the authorize.conf setting: srchIndexesDefault to no value.


B.

Set the authorize.conf setting: srchFilter to no value.


C.

Set the authorize.conf setting: srchIndexesAllowed to no value.


D.

Set the authorize.conf setting: srchJobsQuota to no value.


Expert Solution
Questions # 9:

A new search head cluster is being implemented. Which is the correct command to initialize the deployer node without restarting the search head cluster peers?

Options:

A.

$SPLUNK_HOME/bin/splunk apply shcluster-bundle


B.

$SPLUNK_HOME/bin/splunk apply cluster-bundle


C.

$SPLUNK_HOME/bin/splunk apply shcluster-bundle –action stage


D.

$SPLUNK_HOME/bin/splunk apply cluster-bundle –action stage


Expert Solution
Questions # 10:

What does Splunk do when it indexes events?

Options:

A.

Extracts the top 10 fields.


B.

Extracts metadata fields such as host, source, source type.


C.

Performs parsing, merging, and typing processes on universal forwarders.


D.

Create report acceleration summaries.


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions