SPLK-3002 Exam Questions
100 real SPLK-3002 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Event Analytics and Episode Review
What is an episode?
episodesnotable event groupdefinitionsevent grouping - Question #2Troubleshooting and Optimization
Which index will contain useful error messages when troubleshooting ITSI issues?
_internal indextroubleshootingerror messagesindexes - Question #3Deep Dives and Glass Tables
Which of the following is a recommended best practice for service and glass table design?
glass table designservice designbest practicesimplementation order - Question #4Splunk ITSI Concepts and Environment
Which of the following are deployment recommendations for ITSI? (Choose all that apply.)
deploymenthardware requirementssearch headindexers - Question #5Splunk ITSI Concepts and Environment
What are valid considerations when designing an ITSI Service? (Choose all that apply.)
service designentitiesaccess controlKPI backfill - Question #6Anomaly Detection and Notable Events
Anomaly detection can be enabled on which one of the following?
anomaly detectionKPIconfigurationenablement - Question #7Key Performance Indicators (KPIs)
Which index is used to store KPI values?
itsi_summary_metricsKPI storageindexesdata storage - Question #8Key Performance Indicators (KPIs)
Where are KPI search results stored?
itsi_summary indexKPI resultsdata storageindexes - Question #9Anomaly Detection and Notable Events
Which ITSI functions generate notable events? (Choose all that apply.)
notable eventsKPI thresholdsanomaly detectioncorrelation search - Question #10Data Inputs and Services
Which of the following describes a way to delete multiple duplicate entities in ITSI?
entity managementdeleteentity commandCSV uploadduplicate entities - Question #11Splunk ITSI Concepts and Environment
Which capabilities are enabled through "teams"?
teamsaccess controlservice restrictionsUI views - Question #12Anomaly Detection and Notable Events
Besides creating notable events, what are the default alert actions a correlation search can execute? (Choose all that apply.)
correlation searchalert actionsemailRSS feed - Question #13Anomaly Detection and Notable Events
Within a correlation search, dynamic field values can be specified with what syntax?
correlation searchdynamic fieldsfield syntaxfield values - Question #14Key Performance Indicators (KPIs)
In maintenance mode, which features of KPIs still function?
maintenance modeKPI searchesmaintenance windowsKPI behavior - Question #15Event Analytics and Episode Review
Which index contains ITSI Episodes?
episodesitsi_grouped_alertsindexesepisode storage - Question #16Deep Dives and Glass Tables
Which of the following best describes a default deep dive?
deep divedefault viewKPIsservice KPIs - Question #17Event Analytics and Episode Review
Which of the following describes enabling smart mode for an aggregation policy?
aggregation policysmart modenotable eventspolicy configuration - Question #18Splunk ITSI Concepts and Environment
Which of the following are the default ports that must be configured on Splunk to use ITSI?
default portsSplunkWebSplunkDHTTP event collector - Question #19Data Inputs and Services
Which of the following is a good use case regarding defining entities for a service?
entitiesentity aliasesKPI splittingservice design - Question #20Key Performance Indicators (KPIs)
For which ITSI function is it a best practice to use a 15-30 minute time buffer?
adaptive thresholdingtime bufferbest practicesKPI configuration - Question #21Splunk ITSI Concepts and Environment
There are two departments using ITSI. Finance and Sales. Analysts in each department should not be allowed to see each other's services. What are the role configuration steps requi...
role-based access controlteam permissionsitoa rolesrole inheritance - Question #22Key Performance Indicators (KPIs)
How do you automatically restrict a KPI to only the entities in its service, and generate KPI values for each entity?
split by entityfilter to entitiesKPI entity filteringentity-level KPI - Question #23Splunk ITSI Concepts and Environment
Which of the following items describe ITSI Backup and Restore functionality? (Choose all that apply.)
backup and restorekvstore_to_jsonKV StoreITSI configuration backup - Question #24Splunk ITSI Concepts and Environment
When installing ITSI to support a Distributed Search Architecture, which of the following items apply? (Choose all that apply.)
distributed searchSA-IndexCreationcluster deployerITSI installation - Question #25Key Performance Indicators (KPIs)
Which of the following is a valid type of Multi-KPI Alert?
Multi-KPI alertsalert typesvalue over timeKPI alerting - Question #26Key Performance Indicators (KPIs)
When must a service define entity rules?
entity rulesservice entitiesKPI entity filteringservice configuration - Question #27Splunk ITSI Concepts and Environment
When in maintenance mode, which of the following is accurate?
maintenance modeKPI suppressionservice healthmaintenance window - Question #28Anomaly Detection and Notable Events
In which index are active notable events stored?
notable events indexitsi_tracked_alertsnotable event storageindex configuration - Question #29Splunk ITSI Concepts and Environment
After ITSI is initially deployed for the operations department at a large company, another department would like to use ITSI but wants to keep their information private from the op...
teamsservice permissionsdata isolationmulti-tenant ITSI - Question #30Key Performance Indicators (KPIs)
What is the range for a normal Service Health score category?
service health scorehealth score thresholdsnormal rangescore categories - Question #31Key Performance Indicators (KPIs)
Which of the following are characteristics of ITSI service dependencies? (select all that apply)
service dependenciesdependent service KPIServiceHealthScoreKPI importance level - Question #32Anomaly Detection and Notable Events
Which of the following can generate notable events?
notable event generationcorrelation searchesevent sourcesnotable events - Question #33Anomaly Detection and Notable Events
To use Adaptive Threshholding, what is the minimum requirement for a set of KPI data?
adaptive thresholdingminimum data requirementthreshold trainingKPI data history - Question #34Event Analytics and Episode Review
There are two Smart Mode configuration settings that control how fields affect grouping. Which of these is correct?
Smart Modeevent groupingtext similaritycategory similarity - Question #35Event Analytics and Episode Review
How can admins manually control groupings of notable events?
event groupingaggregation policiesnotable event managementmanual grouping - Question #36Deep Dives and Glass Tables
Which of the following is a characteristic of custom deep dives?
custom deep divesdeep dive lanesmetric lanesKPI lanes - Question #37Troubleshooting and Optimization
When troubleshooting KPI search performance, which search names in job activity identify base searches?
KPI search performancebase searchesjob activitysearch naming convention - Question #38Splunk ITSI Concepts and Environment
Which of the following items describe ITSI teams? (select all that apply)
ITSI teamsglobal teamteam administrationservice ownership - Question #39Splunk ITSI Concepts and Environment
Which of the following are characteristics of service templates? (select all that apply)
service templatesKPI thresholdsentity rulestemplate instantiation - Question #40Deep Dives and Glass Tables
What can a KPI widget on a glass table drill down into?
glass tablesKPI widgetdrilldowndeep dive navigation - Question #41Anomaly Detection and Notable Events
Which of the following is a characteristic of notable event groups?
notable event groupsevent correlationitsi_tracked_alertsgroup characteristics - Question #42Key Performance Indicators (KPIs)
Which of the following services often has KPIs but no entities?
business serviceservice typesKPIsentities - Question #43Event Analytics and Episode Review
When working with a notable event group in the Notable Events Review dashboard, which of the following can be set at the individual or group level?
notable event groupsseveritystatusowner assignment - Question #44Anomaly Detection and Notable Events
Which anomaly detection algorithm is included within ITSI?
anomaly detectionentity cohesionML algorithms - Question #45Splunk ITSI Concepts and Environment
Which ITSI components are required before a module can be created?
ITSI modulesdatamodelsmodule prerequisitesITSI components - Question #46Deep Dives and Glass Tables
Which is the least permissive role required to modify default deep dives?
deep divesITSI rolesitoa_adminpermissions - Question #47Anomaly Detection and Notable Events
How can Service Now incidents be created automatically when a Multi-KPI alert triggers? (select all that apply)
ServiceNow integrationMulti-KPI alertsnotable event aggregation policyalert actions - Question #48Splunk ITSI Concepts and Environment
Which of the following is a good use case for creating a custom module?
custom modulesKPI base searchesITSI migrationmodule use cases - Question #49Anomaly Detection and Notable Events
Within a correlation search, how can a service be associated?
correlation searchesservice associationservice fieldconfiguration - Question #51Troubleshooting and Optimization
For which ITSI function is it a best practice to use a 15-30 minute time buffer?
maintenance windowstime bufferbest practices