Spring Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Splunk IT Service Intelligence Certified Admin Exam Question and Answers

Splunk IT Service Intelligence Certified Admin Exam

Last Update Feb 28, 2026
Total Questions : 96

We are offering FREE SPLK-3002 Splunk exam questions. All you do is to just go and sign up. Give your details, prepare SPLK-3002 free exam questions and then go for complete pool of Splunk IT Service Intelligence Certified Admin Exam test questions that will help you more.

SPLK-3002 pdf

SPLK-3002 PDF

$36.75  $104.99
SPLK-3002 Engine

SPLK-3002 Testing Engine

$43.75  $124.99
SPLK-3002 PDF + Engine

SPLK-3002 PDF + Testing Engine

$57.75  $164.99
Questions 1

Besides creating notable events, what are the default alert actions a correlation search can execute? (Choose all that apply.)

Options:

A.  

Ping a host.

B.  

Send email.

C.  

Include in RSS feed.

D.  

Run a script.

Discussion 0
Questions 2

In which index are active notable events stored?

Options:

A.  

itsi_notable_archive

B.  

itsi_notable_audit

C.  

itsi_tracked_alerts

D.  

itsi_tracked_groups

Discussion 0
Questions 3

Which anomaly detection algorithm fulfills the paired monitoring requirement?

Options:

A.  

Detection algorithm: Trending anomaly detection

Monitoring requirement: Produce an alert when an entity deviates from its historical behavior.

B.  

Detection algorithm: Entity cohesion anomaly detection

Monitoring requirement: Produce an alert when one entity in the KPI is not behaving similar to other entities in the KPI.

C.  

Detection algorithm: Trending anomaly detection

Monitoring requirement: Produce an alert when one entity in the KPI is not behaving similar to other entities in the KPI.

D.  

Detection algorithm: Entity cohesion anomaly detection

Monitoring requirement: Produce an alert when multiple KPIs in the service deviate from their historical behaviors.

Discussion 0
Questions 4

Which of the following items describe ITSI Backup and Restore functionality? (Choose all that apply.)

Options:

A.  

A pre-configured default ITSI backup job is provided that can be modified, but not deleted.

B.  

ITSI backup is inclusive of KV Store, ITSI Configurations, and index dependencies.

C.  

kvstore_to_json.py can be used in scripts or command line to backup ITSI for full or partial backups.

D.  

ITSI backups are stored as a collection of JSON formatted files.

Discussion 0
Questions 5

Helga has a web service that depends on the database service to provide her website. She configures the database’s “Heartbeat” KPI to be a dependency in the web service. When viewing the services in the Service Analyzer tree‑view she sees a dotted line between the database service and the web service.

What is the meaning of the dotted line and how can Helga fix it?

Options:

A.  

The “Heartbeat” KPI is not currently affecting the web service health score. Helga needs to make sure the Heartbeat KPI importance value is set to 0.

B.  

There is a cyclic dependency between the two services. Helga needs to make sure that database service doesn’t have any erroneous dependencies.

C.  

There is a cyclic dependency between the two services. Helga needs to add additional dependencies to change the dotted line to a solid line.

D.  

The “Heartbeat” KPI is not currently affecting the web service health score. Helga needs to make sure the web service KPIs’ importance are all set to 11.

Discussion 0
Questions 6

Which index will contain useful error messages when troubleshooting ITSI issues?

Options:

A.  

_introspection

B.  

_internal

C.  

itsi_summary

D.  

itsi_notable_audit

Discussion 0
Questions 7

In distributed search, which components need to be installed on instances other than the search head?

Options:

A.  

SA-IndexCreation and SA-ITSI-Licensechecker on indexers.

B.  

SA-IndexCreation and SA-ITOA on indexers; SA-ITSI-Licensechecker and SA-UserAccess on the license master.

C.  

SA-IndexCreation on idexers; SA-ITSI-Licensechecker and SA-UserAccess on the license master.

D.  

SA-ITSI-Licensechecker on indexers.

Discussion 0
Questions 8

When installing ITSI to support a Distributed Search Architecture, which of the following items apply? (Choose all that apply.)

Options:

A.  

Copy SA-IndexCreation to all indexers.

B.  

Copy SA-IndexCreation to the etc/apps directory on the index cluster master node.

C.  

Extract installer package into etc/apps directory of the cluster deployer node.

D.  

Extract ITSI app package into etc/apps directory of search head.

Discussion 0
Questions 9

Which of the following are characteristics of service templates? (select all that apply)

Options:

A.  

Service templates can be modified after services are instantiated from it.

B.  

Service templates contain KPIs and KPI thresholds.

C.  

Service templates can contain specific or generic entity rules.

D.  

Service templates contain domain specific dashboards and deep dives.

Discussion 0
Questions 10

Which of the following is a good use case regarding defining entities for a service?

Options:

A.  

Automatically associate entities to services using multiple entity aliases.

B.  

All of the entities have the same identifying field name.

C.  

Being able to split a CPU usage KPI by host name.

D.  

KPI total values are aggregated from multiple different category values in the source events.

Discussion 0
Questions 11

Which of the following is part of setting up a new aggregation policy?

Options:

A.  

Filtering criteria

B.  

Policy version

C.  

Review order

D.  

Module rules

Discussion 0
Questions 12

There are two Smart Mode configuration settings that control how fields affect grouping. Which of these is correct?

Options:

A.  

Text deviation and category deviation.

B.  

Text similarity and category deviation.

C.  

Text similarity and category similarity.

D.  

Text deviation and category similarity.

Discussion 0
Questions 13

How should entities be handled during the data audit phase of requirements gathering?

Options:

A.  

Entity meta-data for info and aliases should be identified and recorded as requirements.

B.  

Entities should be noted based upon Service KPI requirements such as 'by host' or 'by product line'.

C.  

Entities must be identified for every Service KPI defined and recorded in requirements.

D.  

Entities identified should be included in the entity filtering requirements, such as 'by processld' or 'by host'.

Discussion 0
Questions 14

Which of the following is an advantage of an adaptive time threshold?

Options:

A.  

Automatically alerting when KPI value patterns change over time.

B.  

Automatically adjusting thresholds as normal KPI values change over time.

C.  

Automatically adjusting to holiday schedules.

D.  

Automatically predicting future degradation of KPI values over time.

Discussion 0
Questions 15

How can Service Now incidents be created automatically when a Multi-KPI alert triggers? (select all that apply)

Options:

A.  

By creating a custom etc/apps/SA-lTOA/workflow_rules. conf

B.  

By linking Entities to Service-Now configuration items.

C.  

By creating a notable event aggregation policy with a SNOW incident action.

D.  

By editing the associated correlation search and specifying an alert action.

Discussion 0
Questions 16

Buttercup Retail sells t‑shirts both online and in stores. The IT Operations team is effectively monitoring the digital infrastructure. However, the executive leadership has expressed frustration in understanding what the related business impacts are of IT incidents.

Which of the following entities would give Buttercup Retail executives the most impactful visibility?

Options:

A.  

store, product, payment type

B.  

store, season, customer age

C.  

host, browser type, software version

D.  

host, network interface, datacenter

Discussion 0
Questions 17

What happens when an anomaly is detected?

Options:

A.  

A separate correlation search needs to be created in order to see it.

B.  

A SNMP trap will be sent.

C.  

An anomaly alert will appear in core splunk, in index=main.

D.  

An anomaly alert will appear as a notable event in Episode Review.

Discussion 0
Questions 18

Which of the following best describes an ITSI Glass Table?

Options:

A.  

A view which displays a system topology overlaid with KPI metrics.

B.  

A view which describes a topology.

C.  

A dashboard which displays a system topology.

D.  

A view showing KPI values in a variety of visual styles.

Discussion 0
Questions 19

ITSI Saved Search Scheduling is configured to use realtime_schedule = 0. Which statement is accurate about this configuration?

Options:

A.  

If this value is set to 0, the scheduler bases its determination of the next scheduled search execution time on the current time.

B.  

If this value is set to 0, the scheduler bases its determination of the next scheduled search on the last search execution time.

C.  

If this value is set to 0, the scheduler may skip scheduled execution periods.

D.  

If this value is set to 0, the scheduler might skip some execution periods to make sure that the scheduler is executing the searches running over the most recent time range.

Discussion 0
Questions 20

Which of the following is a recommended best practice for ITSI installation?

Options:

A.  

ITSI should not be installed on search heads that have Enterprise Security installed.

B.  

Before installing ITSI, make sure the Common Information Model (CIM) is installed.

C.  

Install the Machine Learning Toolkit app if anomaly detection must be configured.

D.  

Install ITSI on one search head in a search head cluster and migrate the configuration bundle to other search heads.

Discussion 0
Questions 21

Which glass table feature can be used to toggle displaying KPI values from more than one service on a single widget?

Options:

A.  

Service templates.

B.  

Service dependencies.

C.  

Ad-hoc search.

D.  

Service swapping.

Discussion 0
Questions 22

To use Adaptive Threshholding, what is the minimum requirement for a set of KPI data?

Options:

A.  

14 days old.

B.  

7 days old.

C.  

30 days old.

D.  

10 days old.

Discussion 0
Questions 23

Which of the following is a good use case for creating a custom module?

Options:

A.  

Modules are required to create entity and service import searches.

B.  

Modules are required to be able to create custom visualizations for deep dives.

C.  

Making it easy to migrate KPI base searches and related visualizations to other ITSI installations.

D.  

Creating a service template to make it easy to automatically create new services during service and entity import.

Discussion 0
Questions 24

Which of the following is an advantage of using adaptive time thresholds?

Options:

A.  

Automatically update thresholds daily to manage dynamic changes to KPI values.

B.  

Automatically adjust KPI calculation to manage dynamic event data.

C.  

Automatically adjust aggregation policy grouping to manage escalating severity.

D.  

Automatically adjust correlation search thresholds to adjust sensitivity over time.

Discussion 0
Questions 25

Which is the least permissive role required to modify default deep dives?

Options:

A.  

itoa_analyst

B.  

admin

C.  

power

D.  

itoa_admin

Discussion 0
Questions 26

Which of the following is a best practice when configuring maintenance windows?

Options:

A.  

Disable any glass tables that reference a KPI that is part of an open maintenance window.

B.  

Develop a strategy for configuring a service’s notable event generation when the service’s maintenance window is open.

C.  

Give the maintenance window a buffer, for example, 15 minutes before and after actual maintenance work.

D.  

Change the color of services and entities that are part of an open maintenance window in the service analyzer.

Discussion 0
Questions 27

Which of the following best describes a default deep dive?

Options:

A.  

It initially shows the health scores for all services.

B.  

It initially shows the highest importance KPIs.

C.  

It initially shows all of the KPIs for a selected service.

D.  

It initially shows all the entity swim lanes.

Discussion 0
Questions 28

Which of the following is a good use case for a Multi-KPI alert?

Options:

A.  

Alerting when the values of two or more KPIs go into maintenance mode.

B.  

Alerting when the trend of two or more KPIs indicates service failure is imminent.

C.  

Alerting when two or more KPIs are deviating from their typical pattern.

D.  

Alerting when comparing the values of two or more KPIs indicates an unusual condition is occurring.

Discussion 0