SPLK-2002(205Q) Exam Questions
202 real SPLK-2002(205Q) exam questions with expert-verified answers and explanations. Page 1 of 5.
- Question #1Data Management and Indexing
Which of the following will cause the greatest reduction in disk size requirements for a cluster of N indexers running Splunk Enterprise Security?
data model accelerationdisk storageindexer clusterstorage optimization - Question #2Indexer Clustering
Stakeholders have identified high availability for searchable data as their top priority. Which of the following best addresses this requirement?
search factorhigh availabilityindexer clustersearchable copies - Question #3Splunk Deployment Planning
Search dashboards in the Monitoring Console indicate that the distributed deployment is approaching its capacity. Which of the following options will provide the most search perfor...
search performancecapacity planningindexer scalingdistributed deployment - Question #4Data Management and Indexing
A Splunk architect has inherited the Splunk deployment at Buttercup Games and end users are complaining that the events are inconsistently formatted for a web source. Further inves...
event parsingheavy forwarderprops.confindex-time processing - Question #5Splunk License Management
A customer has installed a 500GB Enterprise license. They also purchased and installed a 300GB, no enforcement license on the same license master. How much data can the customer in...
license managementno enforcement licenselicense stackingsearch lockout - Question #6Search Head Clustering
What does the deployer do in a Search Head Cluster (SHC)? (Select all that apply.)
deployersearch head clusterapp distributionconfiguration management - Question #7Data Management and Indexing
When using the props.conf LINE_BREAKER attribute to delimit multi-line events, the SHOULD_LINEMERGE attribute should be set to what?
LINE_BREAKERSHOULD_LINEMERGEprops.confevent breaking - Question #8Splunk Deployment Planning
Which of the following should be included in a deployment plan?
deployment planningdata inventorytopology diagramsstakeholder management - Question #10Data Management and Indexing
Which index-time props.conf attributes impact indexing performance? (Select all that apply.)
index-time processingprops.confindexing performanceSHOULD_LINEMERGE - Question #11Forwarder Management
Which of the following are client filters available in serverclass.conf? (Select all that apply.)
serverclass.confdeployment serverclient filtersforwarder management - Question #12Monitoring and Troubleshooting
What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza?
tailing_processor.logmonitor stanzaregex troubleshootinglog files - Question #13Monitoring and Troubleshooting
Which Splunk tool offers a health check for administrators to evaluate the health of their Splunk deployment?
Monitoring Consolehealth checkdeployment healthadministration tools - Question #14Indexer Clustering
In a four site indexer cluster, which configuration stores two searchable copies at the origin site, one searchable copy at site2, and a total of four searchable copies?
site_search_factormulti-site clusterindexer clustersite configuration - Question #15Splunk Deployment Planning
Which of the following is true regarding Splunk Enterprise's performance? (Select all that apply.)
search performancecapacity planningsearch peersconcurrent searches - Question #16Splunk License Management
Which Splunk Enterprise offering has its own license?
Universal Forwarderforwarder licensingSplunk componentsfree license - Question #17Monitoring and Troubleshooting
Which component in the splunkd.log will log information related to bad event breaking?
splunkd.logAggregatorMiningProcessorevent breakinglog components - Question #18Indexer Clustering
Which Splunk server role regulates the functioning of indexer cluster?
Cluster MasterMaster Nodeindexer clustercluster management - Question #19Search Head Clustering
When adding or rejoining a member to a search head cluster, the following error is displayed: Error pulling configurations from the search head cluster captain; consider performing...
search head clusterconfiguration syncSHC member resynctroubleshooting - Question #20Data Management and Indexing
Which of the following commands is used to clear the KV store?
KV storesplunk CLIkvstore maintenanceclean command - Question #21Performance Tuning
Indexing is slow and real-time search results are delayed in a Splunk environment with two indexers and one search head. There is ample CPU and memory available on the indexers. Wh...
indexing performanceparallel ingestion pipelinesserver.confperformance tuning - Question #22Splunk Deployment Planning
The guidance Splunk gives for estimating size on for syslog data is 50% of original data size. How does this divide between files in the index?
index sizingrawdatatsidxsyslog - Question #23Splunk Deployment Planning
In an existing Splunk environment, the new index buckets that are created each day are about half the size of the incoming data. Within each bucket, about 30% of the space is used...
indexer clusteringdisk sizingreplication factorsearch factor - Question #24Search Head Cluster Management
A three-node search head cluster is skipping a large number of searches across time. What should be done to increase scheduled search capacity on the search head cluster?
search head clusterscheduled searcheslimits.confsearch capacity - Question #25Splunk Forwarder Management
The frequency in which a deployment client contacts the deployment server is controlled by what?
deployment clientdeploymentclient.confphoneHomeIntervalInSecspolling interval - Question #26Indexer Cluster Management
To activate replication for an index in an indexer cluster, what attribute must be configured in indexes.conf on all peer nodes?
indexer clusteringindexes.confrepFactorreplication - Question #27Splunk Forwarder Management
Which of the following clarification steps should be taken if apps are not appearing on a deployment client? (Select all that apply.)
deployment serverserverclass.confdeploymentclient.conftroubleshooting - Question #28Splunk Deployment Planning
What is the minimum reference server specification for a Splunk indexer?
hardware sizingindexerCPU coresRAM - Question #29Splunk Security
Which of the following security options must be explicitly configured (i.e. which options are not enabled by default)?
certificate authenticationTLS/SSLforwarder-indexer securitydefault security - Question #30Splunk Troubleshooting
Which of the following artifacts are included in a Splunk diag file? (Select all that apply.)
diaginternal logsconfiguration filesdiagnostics - Question #31Indexer Cluster Management
Which command will permanently decommission a peer node operating in an indexer cluster?
indexer clusteringpeer node decommissionCLI commandsoffline - Question #32License Management
Which CLI command converts a Splunk instance to a license slave?
licensinglicense slaveCLIlicenser-localslave - Question #33Splunk Monitoring and Troubleshooting
Splunk Enterprise platform instrumentation refers to data that the Splunk Enterprise deployment logs in the _introspection index. Which of the following logs are included in this i...
_introspection indexplatform instrumentationdisk_objects.logresource_usage.log - Question #34Splunk Troubleshooting
Which of the following can a Splunk diag contain?
diagdiagnosticsinternal logsserver specs - Question #35Indexer Cluster Management
Which of the following are true statements about Splunk indexer clustering?
indexer clusteringversion compatibilitymaster nodepeer nodes - Question #36Splunk Deployment Planning
A customer plans to ingest 600 GB of data per day into Splunk. They will have six concurrent users, and they also want high data availability and high search performance. The custo...
capacity planningindexer sizinghigh availabilityclustering - Question #37Search Head Cluster Management
To reduce the captain's work load in a search head cluster, what setting will prevent scheduled searches from running on the captain?
search head clustercaptain workloadcaptain_is_adhoc_searchheadscheduled searches - Question #38License Management
At which default interval does metrics.log generate a periodic report regarding license utilization?
metrics.loglicense utilizationlogging intervalinternal logging - Question #39Search Head Cluster Management
Which of the following is a good practice for a search head cluster deployer?
search head clusterdeployerconfiguration distributionnon-replicable configs - Question #40Splunk Forwarder Management
A new Splunk customer is using syslog to collect data from their network devices on port 514. What is the best practice for ingesting this data into Splunk?
syslog ingestionuniversal forwarderdata ingestion best practicesnetwork devices - Question #41License Management
Which Splunk internal index contains license-related events?
_internal indexlicense eventsinternal indexeslicensing - Question #42Search Head Clustering
Which of the following statements describe a Search Head Cluster (SHC) captain? (Select all that apply.)
SHC captainsearch head clusterjob schedulingKV store - Question #43KV Store Configuration
Before users can use a KV store, an admin must create a collection. Where is a collection is defined?
KV storecollections.confconfiguration files - Question #44Distributed Deployment
Which search will show all deployment client messages from the client (UF)?
deployment clientuniversal forwarder_internal indexsearch query - Question #45Indexer Clustering
To optimize the distribution of primary buckets; when does primary rebalancing automatically occur? (Select all that apply.)
primary rebalancingindexer clusterbucket managementpeer node - Question #46Search Head Clustering
Which search head cluster component is responsible for pushing knowledge bundles to search peers, replicating configuration changes to search head cluster members, and scheduling j...
SHC captainknowledge bundlejob schedulingconfiguration replication - Question #47Search Head Clustering
Configurations from the deployer are merged into which location on the search head cluster member?
deployerconfiguration managementsearch head clusterapp deployment - Question #48Index Configuration
When Splunk indexes data in a non-clustered environment, what kind of files does it create by default?
indexingtsidx filesrawdataindex files - Question #49Deployment Planning
How does IT Service Intelligence (ITSI) impact the planning of a Splunk deployment?
ITSIdeployment planninghardware resourcesKPIs - Question #50Deployment Planning
In the deployment planning process, when should a person identify who gets to see network data?
deployment planningdata policyaccess controlnetwork data - Question #51KV Store Configuration
The KV store forms its own cluster within a SHC. What is the maximum number of SHC members KV store will form?
KV storeSHC memberscluster limits