SPLK-2002(205Q) Exam Questions
202 real SPLK-2002(205Q) exam questions with expert-verified answers and explanations. Page 3 of 5.
- Question #103Indexer Cluster Management
Which of the following configuration attributes must be set in server, conf on the cluster manager in a single-site indexer cluster?
indexer clusteringserver.confcluster manager configurationsingle-site cluster - Question #104Index Management
An index has large text log entries with many unique terms in the raw data. Other than the raw data, which index components will take the most space?
index storagetsidx filesindex internalsunique terms - Question #105Search Head Cluster Management
A search head cluster with a KV store collection can be updated from where in the KV store collection?
KV storesearch head clusteringdata updatesSHC - Question #106Splunk Capacity Planning and Deployment
Which of the following items are important sizing parameters when architecting a Splunk environment? (select all that apply)
capacity planningsizingconcurrent usersdata volume - Question #107Forwarder and Deployment Management
If there is a deployment server with many clients and one deployment client is not updating apps, which of the following should be done first?
deployment serverdeployment clienttroubleshootingsplunkd.log - Question #109Forwarder Management
When should a Universal Forwarder be used instead of a Heavy Forwarder?
universal forwarderheavy forwarderforwarder selectionhigh-velocity data - Question #110Search Head Cluster Management
Which of the following most improves KV Store resiliency?
KV storesearch head clusteringnetwork latencyresiliency - Question #111Search Head Cluster Management
Which of the following Splunk deployments has the recommended minimum components for a high- availability search head cluster?
search head clusteringhigh availabilityminimum componentsdeployer - Question #112Forwarder Management
What is needed to ensure that high-velocity sources will not have forwarding delays to the indexers?
forwarder throughputmaxKBpslimits.confhigh-velocity data - Question #113Troubleshooting
Users who receive a link to a search are receiving an "Unknown sid" error message when they open the link. Why is this happening?
search job expirationSIDsearch artifactstroubleshooting - Question #114Forwarder Management
Why should intermediate forwarders be avoided when possible?
forwarder topologyintermediate forwardersperformance bottlenecksdata pipeline - Question #115Splunk Architecture Design
A Splunk deployment is being architected and the customer will be using Splunk Enterprise Security (ES) and Splunk IT Service Intelligence (ITSI). Through data onboarding and sizin...
Enterprise SecurityITSIsearch head clusteringarchitecture design - Question #116Troubleshooting
How can internal logging levels in a Splunk environment be changed to troubleshoot an issue? (select all that apply)
logging levelstroubleshootingSplunk Weblog-local.cfg - Question #117Search Head Cluster Management
Other than high availability, which of the following is a benefit of search head clustering?
search head clusteringknowledge object replicationhigh availabilitySHC benefits - Question #118Search Head Cluster Management
By default, what happens to configurations in the local folder of each Splunk app when it is deployed to a search head cluster?
app deploymentsearch head clusteringconf file managementdeployer - Question #119Indexer Cluster Management
A Splunk environment collecting 10 TB of data per day has 50 indexers and 5 search heads. A single- site indexer cluster will be implemented. Which of the following is a best pract...
replication factorindexer clusteringdata resiliencybest practices - Question #120Troubleshooting
Which Splunk log file would be the least helpful in troubleshooting a crash?
troubleshootinglog filescrash analysissplunk_instrumentation.log - Question #121Indexer Cluster Management
Which of the following use cases would be made possible by multi-site clustering? (select all that apply)
multi-site clusteringsearch affinitysite failoverWAN traffic reduction - Question #122Troubleshooting
Which of the following would be the least helpful in troubleshooting contents of Splunk configuration files?
troubleshooting toolsbtooldiagnostic logsconfiguration files - Question #123Indexer Cluster Management
What is the expected minimum amount of storage required for data across an indexer cluster with the following input and parameters? - Raw data = 15 GB per day - Index files = 35 GB...
indexer clusterstorage capacity planningreplication factorsearch factor - Question #124Troubleshooting
A monitored log file is changing on the forwarder. However, Splunk searches are not finding any new data that has been added. What are possible causes? (select all that apply)
file monitoringfishbucketCRC checkinputs.conf - Question #125Troubleshooting
Which of the following is a problem that could be investigated using the Search Job Inspector?
Search Job Inspectorsearch troubleshootingsearch performance - Question #126Troubleshooting
When troubleshooting a situation where some files within a directory are not being indexed, the ignored files are discovered to have long headers. What is the first thing that shou...
initCrcLengthinputs.conffile monitoringCRC - Question #127Indexer Cluster Management
In an indexer cluster, what tasks does the cluster manager perform? (select all that apply)
cluster managerindexer clusterIndexer Discoveryapp bundle distribution - Question #128Troubleshooting
New data has been added to a monitor input file. However, searches only show older data. Which splunkd. log channel would help troubleshoot this issue?
splunkd.logTailingProcessorfile monitoringtroubleshooting channels - Question #129Splunk Deployment Planning
Determining data capacity for an index is a non-trivial exercise. Which of the following are possible considerations that would affect daily indexing volume? (select all that apply...
capacity planningindexing volumepeak data ratesdata sources - Question #130Data Ingestion Configuration
Splunk Enterprise performs a cyclic redundancy check (CRC) against the first and last bytes to prevent the same file from being re-indexed if it is rotated or renamed. What is the...
CRCinitCrcLengthfile monitoringdefault settings - Question #131Index Management
Users are asking the Splunk administrator to thaw recently-frozen buckets very frequently. What could the Splunk administrator do to reduce the need to thaw buckets?
bucket lifecyclefrozenTimePeriodInSecsdata retentionindexes.conf - Question #132Splunk Deployment Architecture
When should a dedicated deployment server be used?
deployment serverdeployment clientsSplunk architecture - Question #133Troubleshooting
Which Splunk internal field can confirm duplicate event issues from failed file monitoring?
_indextimeduplicate eventsinternal fieldsfile monitoring - Question #134Splunk Deployment Planning
What information is needed about the current environment before deploying Splunk? (select all that apply)
deployment planningrequirements gatheringdata sourcesdeployment goals - Question #135Forwarder Management
Which of the following options in limits, conf may provide performance benefits at the forwarding tier?
limits.confparallelIngestionPipelinesforwarding tierperformance tuning - Question #136Indexer Cluster Management
How many cluster managers are required for a multisite indexer cluster?
multisite indexer clustercluster managercluster architecture - Question #137Search Head Cluster Management
On search head cluster members, where in $splunk_home does the Splunk Deployer deploy app content by default?
search head clusterdeployerslave-appsapp deployment - Question #138Troubleshooting
Several critical searches that were functioning correctly yesterday are not finding a lookup table today. Which log file would be the best place to start troubleshooting?
lookup tablestroubleshootinglog filesconfiguration changes - Question #139Search Head Cluster Management
Which of the following is a valid use case that a search head cluster addresses?
search head clusterknowledge object replicationhigh availabilitySHC use cases - Question #140License Management
When using ingest-based licensing, what Splunk role requires the license manager to scale?
ingest-based licensinglicense managerSplunk licensingscaling - Question #141Splunk Deployment Planning
Which part of the deployment plan is vital prior to installing Splunk indexer clusters and search head clusters?
deployment planningdeployment topologyindexer clustersearch head cluster - Question #142Splunk Licensing
Data for which of the following indexes will count against an ingest-based license?
ingest-based licenseinternal indexesindex typeslicensing - Question #143Indexer Cluster Management
An indexer cluster is being designed with the following characteristics: - 10 search peers - Replication Factor (RF): 4 - Search Factor (SF): 3 - No SmartStore usage How many searc...
indexer clusterreplication factorsearch factorcluster fault tolerance - Question #144Forwarder Management
A customer is migrating 500 Universal Forwarders from an old deployment server to a new deployment server, with a different DNS name. The new deployment server is configured and ru...
deployment serveruniversal forwarderdeploymentclient.confforwarder migration - Question #145Indexer Cluster Management
What types of files exist in a bucket within a clustered index? (select all that apply)
indexer clusterbucket typesrawdatatsidx - Question #146Index Management
When designing the number and size of indexes, which of the following considerations should be applied?
index designdata retentionaccess controlsingest volume - Question #147Search Head Cluster Management
Which Splunk component is mandatory when implementing a search head cluster?
search head clusterdeployerSHC componentscluster architecture - Question #148Search Head Cluster Management
When implementing KV Store Collections in a search head cluster, which of the following considerations is true?
KV Storesearch head clusterKV Store Primarycluster captain - Question #149Indexer Cluster Management
Which of the following is true for indexer cluster knowledge bundles?
knowledge bundlesindexer clusterapp configurationbundle replication - Question #150Data Onboarding
When preparing to ingest a new data source, which of the following is optional in the data source assessment?
data source assessmentdata onboardingdata retentioningest planning - Question #151Search Optimization
Where in the Job Inspector can details be found to help determine where performance is affected?
Job Inspectorsearch performanceexecution coststroubleshooting - Question #152Search Head Cluster Management
Which command should be run to re-sync a stale KV Store member in a search head cluster?
KV Storesearch head clusterresyncCLI commands - Question #153Search Head Cluster Management
What is the best method for sizing or scaling a search head cluster?
search head clustercapacity planningconcurrent searchesCPU sizing