Filters
Question type

Study Flashcards

In a distributed environment, knowledge object bundles are replicated from the search head to which location on the search peer(s) ?


A) SPLUNK_HOME/var/lib/searchpeers
B) SPLUNK_HOME/var/log/searchpeers
C) SPLUNK_HOME/var/run/searchpeers
D) SPLUNK_HOME/var/spool/searchpeers

Correct Answer

verifed

verified

Which of the following clarification steps should be taken if apps are not appearing on a deployment client? (Select all that apply.)


A) Check serverclass.conf of the deployment server. Check serverclass.conf of the deployment server.
B) Check deploymentclient.conf of the deployment client. deploymentclient.conf of the deployment client.
C) Check the content of SPLUNK_HOME/etc/apps of the deployment server. Check the content of SPLUNK_HOME/etc/apps
D) Search for relevant events in splunkd.log of the deployment server. Search for relevant events in splunkd.log

Correct Answer

verifed

verified

Which of the following statements describe search head clustering? (Select all that apply.)


A) A deployer is required.
B) At least three search heads are needed.
C) Search heads must meet the high-performance reference server requirements.
D) The deployer must have sufficient CPU and network resources to process service requests and push configurations.

Correct Answer

verifed

verified

In which phase of the Splunk Enterprise data pipeline are indexed extraction configurations processed?


A) Input
B) Search
C) Parsing
D) Indexing

Correct Answer

verifed

verified

Which of the following security options must be explicitly configured (i.e. which options are not enabled by default) ?


A) Data encryption between Splunk Web and splunkd.
B) Certificate authentication between forwarders and indexers.
C) Certificate authentication between Splunk Web and search head.
D) Data encryption for distributed search between search heads and indexers.

Correct Answer

verifed

verified

How does the average run time of all searches relate to the available CPU cores on the indexers?


A) Average run time is independent of the number of CPU cores on the indexers.
B) Average run time decreases as the number of CPU cores on the indexers decreases.
C) Average run time increases as the number of CPU cores on the indexers decreases.
D) Average run time increases as the number of CPU cores on the indexers increases.

Correct Answer

verifed

verified

When using the props.conf LINE_BREAKER attribute to delimit multi-line events, the SHOULD_LINEMERGE attribute should be set to what?


A) Auto
B) None
C) true
D) false

Correct Answer

verifed

verified

Splunk Enterprise platform instrumentation refers to data that the Splunk Enterprise deployment logs in the _introspection index. Which of the following logs are included in this index? (Select all that apply.)


A) audit.log
B) metrics.log
C) disk_objects.log
D) resource_usage.log

Correct Answer

verifed

verified

Which of the following statements describe a Search Head Cluster (SHC) captain? (Select all that apply.)


A) Is the job scheduler for the entire SHC.
B) Manages alert action suppressions (throttling) .
C) Synchronizes the member list with the KV store primary.
D) Replicates the SHC's knowledge bundle to the search peers.

Correct Answer

verifed

verified

Which search head cluster component is responsible for pushing knowledge bundles to search peers, replicating configuration changes to search head cluster members, and scheduling jobs across the search head cluster?


A) Master
B) Captain
C) Deployer
D) Deployment server

Correct Answer

verifed

verified

Because Splunk indexing is read/write intensive, it is important to select the appropriate disk storage solution for each deployment. Which of the following statements is accurate about disk storage?


A) High performance SAN should never be used.
B) Enable NFS for storing hot and warm buckets.
C) The recommended RAID setup is RAID 10 (1 + 0) .
D) Virtualized environments are usually preferred over bare metal for Splunk indexers.

Correct Answer

verifed

verified

Which Splunk internal index contains license-related events?


A) _audit
B) _license
C) _internal
D) _introspection

Correct Answer

verifed

verified

What does the deployer do in a Search Head Cluster (SHC) ? (Select all that apply.)


A) Distributes apps to SHC members.
B) Bootstraps a clean Splunk install for a SHC.
C) Distributes non-search related and manual configuration file changes.
D) Distributes runtime knowledge object changes made by users across the SHC.

Correct Answer

verifed

verified

What is the minimum reference server specification for a Splunk indexer?


A) 12 CPU cores, 12GB RAM, 800 IOPS
B) 16 CPU cores, 16GB RAM, 800 IOPS
C) 24 CPU cores, 16GB RAM, 1200 IOPS
D) 28 CPU cores, 32GB RAM, 1200 IOPS

Correct Answer

verifed

verified

Which two sections can be expanded using the Search Job Inspector?


A) Execution costs.
B) Saved search history.
C) Search job properties.
D) Optimization suggestions.

Correct Answer

verifed

verified

To activate replication for an index in an indexer cluster, what attribute must be configured in indexes.conf on all peer nodes?


A) repFactor = 0
B) replicate = 0
C) repFactor = auto
D) replicate = auto

Correct Answer

verifed

verified

A Splunk instance has the following settings in SPLUNK_HOME/etc/system/local/server.conf: [clustering] mode = master replication_factor = 2 pass4SymmKey = password123 Which of the following statements describe this Splunk instance? (Select all that apply.)


A) This is a multi-site cluster.
B) This cluster's search factor is 2.
C) This Splunk instance needs to be restarted.
D) This instance is missing the master_uri attribute. This instance is missing the master_uri attribute.

Correct Answer

verifed

verified

What is the logical first step when starting a deployment plan?


A) Inventory the currently deployed logging infrastructure.
B) Determine what apps and use cases will be implemented.
C) Gather statistics on the expected adoption of Splunk for sizing.
D) Collect the initial requirements for the deployment from all stakeholders.

Correct Answer

verifed

verified

Which of the following are true statements about Splunk indexer clustering?


A) All peer nodes must run exactly the same Splunk version.
B) The master node must run the same or a later Splunk version than search heads.
C) The peer nodes must run the same or a later Splunk version than the master node.
D) The search head must run the same or a later Splunk version than the peer nodes.

Correct Answer

verifed

verified

In a four site indexer cluster, which configuration stores two searchable copies at the origin site, one searchable copy at site2, and a total of four searchable copies?


A) site_search_factor = origin:2, site1:2, total:4
B) site_search_factor = origin:2, site2:1, total:4
C) site_replication_factor = origin:2, site1:2, total:4
D) site_replication_factor = origin:2, site2:1, total:4

Correct Answer

verifed

verified

Showing 41 - 60 of 85

Related Exams

Show Answer