Which of the following items are important sizing parameters when architecting a Splunk environment? (select all that apply)
Stakeholders have identified high availability for searchable data as their top priority. Which of the following best addresses this requirement?
(Which Splunk component allows viewing of the LISPY to assist in debugging Splunk searches?)
(A customer has converted a CSV lookup to a KV Store lookup. What must be done to make it available for an automatic lookup?)
(The performance of a specific search is performing poorly. The search must run over All Time and is expected to have very few results. Analysis shows that the search accesses a very large number of buckets in a large index. What step would most significantly improve the performance of this search?)
(If the maxDataSize attribute is set to auto_high_volume in indexes.conf on a 64-bit operating system, what is the maximum hot bucket size?)
Which Splunk internal field can confirm duplicate event issues from failed file monitoring?
At which default interval does metrics.log generate a periodic report regarding license utilization?
An index has large text log entries with many unique terms in the raw data. Other than the raw data, which index components will take the most space?
What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza?
A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)
(If a license peer cannot communicate to a license manager for 72 hours or more, what will happen?)
In search head clustering, which of the following methods can you use to transfer captaincy to a different member? (Select all that apply.)
A customer has installed a 500GB Enterprise license. They also purchased and installed a 300GB, no enforcement license on the same license master. How much data can the customer ingest before the search is locked out?
When adding or rejoining a member to a search head cluster, the following error is displayed:
Error pulling configurations from the search head cluster captain; consider performing a destructive configuration resync on this search head cluster member.
What corrective action should be taken?
Which command is used for thawing the archive bucket?
(A customer creates a saved search that runs on a specific interval. Which internal Splunk log should be viewed to determine if the search ran recently?)
Which of the following statements describe a Search Head Cluster (SHC) captain? (Select all that apply.)
Consider a use case involving firewall data. There is no Splunk-supported Technical Add-On, but the vendor has built one. What are the items that must be evaluated before installing the add-on? (Select all that apply.)
What is needed to ensure that high-velocity sources will not have forwarding delays to the indexers?
What is a Splunk Job? (Select all that apply.)
As a best practice, where should the internal licensing logs be stored?
What does the deployer do in a Search Head Cluster (SHC)? (Select all that apply.)
(An admin removed and re-added search head cluster (SHC) members as part of patching the operating system. When trying to re-add the first member, a script reverted the SHC member to a previous backup, and the member refuses to join the cluster. What is the best approach to fix the member so that it can re-join?)
(Which of the following is a benefit of using SmartStore?)
What is the recommended order of activities in the Splunk deployment process?
A Splunk deployment is being architected and the customer will be using Splunk Enterprise Security (ES) and Splunk IT Service Intelligence (ITSI). Through data onboarding and sizing, it is determined that over 200 discrete KPIs will be tracked by ITSI and 1TB of data per day by ES. What topology ensures a scalable and performant deployment?
When Splunk indexes data in a non-clustered environment, what kind of files does it create by default?
Which component in the splunkd.log will log information related to bad event breaking?
A Splunk instance has crashed, but no crash log was generated. There is an attempt to determine what user activity caused the crash by running the following search:
What does searching for closed_txn=0 do in this search?
Which of the following are client filters available in serverclass.conf? (Select all that apply.)
When should a dedicated deployment server be used?
Which of the following can a Splunk diag contain?
(Based on the data sizing and retention parameters listed below, which of the following will correctly calculate the index storage required?)
• Daily rate = 20 GB / day
• Compress factor = 0.5
• Retention period = 30 days
• Padding = 100 GB
(A customer wishes to keep costs to a minimum, while still implementing Search Head Clustering (SHC). What are the minimum supported architecture standards?)
Because Splunk indexing is read/write intensive, it is important to select the appropriate disk storage solution for each deployment. Which of the following statements is accurate about disk storage?
(What command will decommission a search peer from an indexer cluster?)
(How is the search log accessed for a completed search job?)
Which of the following is unsupported in a production environment?
In a four site indexer cluster, which configuration stores two searchable copies at the origin site, one searchable copy at site2, and a total of four searchable copies?
When adding or decommissioning a member from a Search Head Cluster (SHC), what is the proper order of operations?
Indexing is slow and real-time search results are delayed in a Splunk environment with two indexers and one search head. There is ample CPU and memory available on the indexers. Which of the following is most likely to improve indexing performance?
Which command will permanently decommission a peer node operating in an indexer cluster?
Where in the Job Inspector can details be found to help determine where performance is affected?
Which of the following statements describe search head clustering? (Select all that apply.)
Which of the following Splunk deployments has the recommended minimum components for a high-availability search head cluster?
A multi-site indexer cluster can be configured using which of the following? (Select all that apply.)
The guidance Splunk gives for estimating size on for syslog data is 50% of original data size. How does this divide between files in the index?
A monitored log file is changing on the forwarder. However, Splunk searches are not finding any new data that has been added. What are possible causes? (select all that apply)
Of the following types of files within an index bucket, which file type may consume the most disk?
What is the logical first step when starting a deployment plan?
Configurations from the deployer are merged into which location on the search head cluster member?
(A high-volume source and a low-volume source feed into the same index. Which of the following items best describe the impact of this design choice?)
The frequency in which a deployment client contacts the deployment server is controlled by what?
Which of the following describe migration from single-site to multisite index replication?
(Which of the following has no impact on search performance?)
Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)
Splunk Enterprise platform instrumentation refers to data that the Splunk Enterprise deployment logs in the _introspection index. Which of the following logs are included in this index? (Select all that apply.)
Which of the following options in limits, conf may provide performance benefits at the forwarding tier?
To expand the search head cluster by adding a new member, node2, what first step is required?