3 Months Free Update
3 Months Free Update
3 Months Free Update
The guidance Splunk gives for estimating size on for syslog data is 50% of original data size. How does this divide between files in the index?
What information is needed about the current environment before deploying Splunk? (select all that apply)
Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)
Which of the following Splunk deployments has the recommended minimum components for a high-availability search head cluster?
Which Splunk log file would be the least helpful in troubleshooting a crash?
Which command will permanently decommission a peer node operating in an indexer cluster?
Which of the following is a way to exclude search artifacts when creating a diag?
Which of the following tasks should the architect perform when building a deployment plan? (Select all that apply.)
A search head cluster member contains the following in its server .conf. What is the Splunk server name of this member?
When troubleshooting monitor inputs, which command checks the status of the tailed files?
In search head clustering, which of the following methods can you use to transfer captaincy to a different member? (Select all that apply.)
An index has large text log entries with many unique terms in the raw data. Other than the raw data, which index components will take the most space?
An indexer cluster is being designed with the following characteristics:
• 10 search peers
• Replication Factor (RF): 4
• Search Factor (SF): 3
• No SmartStore usage
How many search peers can fail before data becomes unsearchable?
Which of the following configuration attributes must be set in server, conf on the cluster manager in a single-site indexer cluster?
When converting from a single-site to a multi-site cluster, what happens to existing single-site clustered buckets?
Which of the following security options must be explicitly configured (i.e. which options are not enabled by default)?
Several critical searches that were functioning correctly yesterday are not finding a lookup table today. Which log file would be the best place to start troubleshooting?
A Splunk deployment is being architected and the customer will be using Splunk Enterprise Security (ES) and Splunk IT Service Intelligence (ITSI). Through data onboarding and sizing, it is determined that over 200 discrete KPIs will be tracked by ITSI and 1TB of data per day by ES. What topology ensures a scalable and performant deployment?
A customer currently has many deployment clients being managed by a single, dedicated deployment server. The customer plans to double the number of clients.
What could be done to minimize performance issues?
Which server.conf attribute should be added to the master node's server.conf file when decommissioning a site in an indexer cluster?
Splunk configuration parameter settings can differ between multiple .conf files of the same name contained within different apps. Which of the following directories has the highest precedence?
Which of the following is true regarding the migration of an index cluster from single-site to multi-site?
Which of the following options in limits, conf may provide performance benefits at the forwarding tier?
To reduce the captain's work load in a search head cluster, what setting will prevent scheduled searches from running on the captain?
In a distributed environment, knowledge object bundles are replicated from the search head to which location on the search peer(s)?
When implementing KV Store Collections in a search head cluster, which of the following considerations is true?
A new Splunk customer is using syslog to collect data from their network devices on port 514. What is the best practice for ingesting this data into Splunk?
Determining data capacity for an index is a non-trivial exercise. Which of the following are possible considerations that would affect daily indexing volume? (select all that apply)
Which of the following is a problem that could be investigated using the Search Job Inspector?
Splunk Enterprise performs a cyclic redundancy check (CRC) against the first and last bytes to prevent the same file from being re-indexed if it is rotated or renamed. What is the number of bytes sampled by default?
Which of the following is a valid use case that a search head cluster addresses?
Other than high availability, which of the following is a benefit of search head clustering?
Users are asking the Splunk administrator to thaw recently-frozen buckets very frequently. What could the Splunk administrator do to reduce the need to thaw buckets?
In the deployment planning process, when should a person identify who gets to see network data?