Splunk Enterprise Certified Architect
Last Update May 2, 2024
Total Questions : 160
We are offering FREE SPLK-2002 Splunk exam questions. All you do is to just go and sign up. Give your details, prepare SPLK-2002 free exam questions and then go for complete pool of Splunk Enterprise Certified Architect test questions that will help you more.
In an existing Splunk environment, the new index buckets that are created each day are about half the size of the incoming data. Within each bucket, about 30% of the space is used for rawdata and about 70% for index files.
What additional information is needed to calculate the daily disk consumption, per indexer, if indexer clustering is implemented?
In the deployment planning process, when should a person identify who gets to see network data?
Search dashboards in the Monitoring Console indicate that the distributed deployment is approaching its capacity. Which of the following options will provide the most search performance improvement?
When configuring a Splunk indexer cluster, what are the default values for replication and search factor?
When Splunk indexes data in a non-clustered environment, what kind of files does it create by default?
To optimize the distribution of primary buckets; when does primary rebalancing automatically occur? (Select all that apply.)
Of the following types of files within an index bucket, which file type may consume the most disk?
How does the average run time of all searches relate to the available CPU cores on the indexers?
In a four site indexer cluster, which configuration stores two searchable copies at the origin site, one searchable copy at site2, and a total of four searchable copies?
Which of the following use cases would be made possible by multi-site clustering? (select all that apply)
Which server.conf attribute should be added to the master node's server.conf file when decommissioning a site in an indexer cluster?
Which of the following items are important sizing parameters when architecting a Splunk environment? (select all that apply)
If there is a deployment server with many clients and one deployment client is not updating apps, which of the following should be done first?
Users who receive a link to a search are receiving an "Unknown sid" error message when they open the link.
Why is this happening?
Which Splunk internal field can confirm duplicate event issues from failed file monitoring?
Data for which of the following indexes will count against an ingest-based license?
Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)
Which of the following tasks should the architect perform when building a deployment plan? (Select all that apply.)
New data has been added to a monitor input file. However, searches only show older data.
Which splunkd. log channel would help troubleshoot this issue?
Which of the following Splunk deployments has the recommended minimum components for a high-availability search head cluster?
Because Splunk indexing is read/write intensive, it is important to select the appropriate disk storage solution for each deployment. Which of the following statements is accurate about disk storage?
What information is needed about the current environment before deploying Splunk? (select all that apply)
By default, what happens to configurations in the local folder of each Splunk app when it is deployed to a search head cluster?
In search head clustering, which of the following methods can you use to transfer captaincy to a different member? (Select all that apply.)
A customer currently has many deployment clients being managed by a single, dedicated deployment server. The customer plans to double the number of clients.
What could be done to minimize performance issues?
What types of files exist in a bucket within a clustered index? (select all that apply)
If .delta replication fails during knowledge bundle replication, what is the fall-back method for Splunk?
A Splunk deployment is being architected and the customer will be using Splunk Enterprise Security (ES) and Splunk IT Service Intelligence (ITSI). Through data onboarding and sizing, it is determined that over 200 discrete KPIs will be tracked by ITSI and 1TB of data per day by ES. What topology ensures a scalable and performant deployment?
On search head cluster members, where in $splunk_home does the Splunk Deployer deploy app content by default?
The guidance Splunk gives for estimating size on for syslog data is 50% of original data size. How does this divide between files in the index?
A customer is migrating 500 Universal Forwarders from an old deployment server to a new deployment server, with a different DNS name. The new deployment server is configured and running.
The old deployment server deployed an app containing an updated deploymentclient.conf file to all forwarders, pointing them to the new deployment server. The app was successfully deployed to all 500 forwarders.
Why would all of the forwarders still be phoning home to the old deployment server?
A Splunk architect has inherited the Splunk deployment at Buttercup Games and end users are complaining that the events are inconsistently formatted for a web source. Further investigation reveals that not all weblogs flow through the same infrastructure: some of the data goes through heavy forwarders and some of the forwarders are managed by another department.
Which of the following items might be the cause of this issue?
Which of the following server. conf stanzas indicates the Indexer Discovery feature has not been fully configured (restart pending) on the Master Node?
A)
B)
C)
D)
Which of the following would be the least helpful in troubleshooting contents of Splunk configuration files?
Which of the following statements describe search head clustering? (Select all that apply.)