Several critical searches that were functioning correctly yesterday are not finding a lookup table today. Which log file would be the best place to start troubleshooting?
How does IT Service Intelligence (ITSI) impact the planning of a Splunk deployment?
Which of the following is a problem that could be investigated using the Search Job Inspector?
To reduce the captain's work load in a search head cluster, what setting will prevent scheduled searches from running on the captain?
A Splunk deployment is being architected and the customer will be using Splunk Enterprise Security (ES) and Splunk IT Service Intelligence (ITSI). Through data onboarding and sizing, it is determined that over 200 discrete KPIs will be tracked by ITSI and 1TB of data per day by ES. What topology ensures a scalable and performant deployment?
(The performance of a specific search is performing poorly. The search must run over All Time and is expected to have very few results. Analysis shows that the search accesses a very large number of buckets in a large index. What step would most significantly improve the performance of this search?)
By default, what happens to configurations in the local folder of each Splunk app when it is deployed to a search head cluster?
metrics. log is stored in which index?
Which of the following are true statements about Splunk indexer clustering?
(A customer has an environment with a Search Head Cluster and an indexer cluster. They are troubleshooting license usage data, including indexed volume in bytes per pool, index, host, sourcetype, and source. Where should the license_usage.log file be retrieved from in this environment?)
As a best practice, where should the internal licensing logs be stored?
(What command will decommission a search peer from an indexer cluster?)
(Which command is used to initially add a search head to a single-site indexer cluster?)
To optimize the distribution of primary buckets; when does primary rebalancing automatically occur? (Select all that apply.)
When configuring a Splunk indexer cluster, what are the default values for replication and search factor?
Which Splunk server role regulates the functioning of indexer cluster?
Which tool(s) can be leveraged to diagnose connection problems between an indexer and forwarder? (Select all that apply.)
(A high-volume source and a low-volume source feed into the same index. Which of the following items best describe the impact of this design choice?)
A customer has a multisite cluster with site1 and site2 configured. They want to configure search heads in these sites to get search results only from data stored on their local sites. Which step prevents this behavior?
Which of the following statements describe search head clustering? (Select all that apply.)
(It is possible to lose UI edit functionality after manually editing which of the following files in the deployment server?)
Splunk configuration parameter settings can differ between multiple .conf files of the same name contained within different apps. Which of the following directories has the highest precedence?
Search dashboards in the Monitoring Console indicate that the distributed deployment is approaching its capacity. Which of the following options will provide the most search performance improvement?
Consider a use case involving firewall data. There is no Splunk-supported Technical Add-On, but the vendor has built one. What are the items that must be evaluated before installing the add-on? (Select all that apply.)
How can internal logging levels in a Splunk environment be changed to troubleshoot an issue? (select all that apply)
Splunk Enterprise platform instrumentation refers to data that the Splunk Enterprise deployment logs in the _introspection index. Which of the following logs are included in this index? (Select all that apply.)
Which of the following is a valid use case that a search head cluster addresses?
Which of the following describe migration from single-site to multisite index replication?
(A customer has a Splunk Enterprise deployment and wants to collect data from universal forwarders. What is the best step to secure log traffic?)
Which of the following is true regarding the migration of an index cluster from single-site to multi-site?
(How can a Splunk admin control the logging level for a specific search to get further debug information?)
When adding or rejoining a member to a search head cluster, the following error is displayed:
Error pulling configurations from the search head cluster captain; consider performing a destructive configuration resync on this search head cluster member.
What corrective action should be taken?
In a distributed environment, knowledge object bundles are replicated from the search head to which location on the search peer(s)?
A customer currently has many deployment clients being managed by a single, dedicated deployment server. The customer plans to double the number of clients.
What could be done to minimize performance issues?
An indexer cluster is being designed with the following characteristics:
• 10 search peers
• Replication Factor (RF): 4
• Search Factor (SF): 3
• No SmartStore usage
How many search peers can fail before data becomes unsearchable?
Why should intermediate forwarders be avoided when possible?
When using the props.conf LINE_BREAKER attribute to delimit multi-line events, the SHOULD_LINEMERGE attribute should be set to what?
(A customer has converted a CSV lookup to a KV Store lookup. What must be done to make it available for an automatic lookup?)
Because Splunk indexing is read/write intensive, it is important to select the appropriate disk storage solution for each deployment. Which of the following statements is accurate about disk storage?
Which props.conf setting has the least impact on indexing performance?
The KV store forms its own cluster within a SHC. What is the maximum number of SHC members KV store will form?
(A new Splunk Enterprise deployment is being architected, and the customer wants to ensure that the data to be indexed is encrypted. Where should TLS be turned on in the Splunk deployment?)
A multi-site indexer cluster can be configured using which of the following? (Select all that apply.)
What is the algorithm used to determine captaincy in a Splunk search head cluster?
When troubleshooting a situation where some files within a directory are not being indexed, the ignored files are discovered to have long headers. What is the first thing that should be added to inputs.conf?
A Splunk instance has the following settings in SPLUNK_HOME/etc/system/local/server.conf:
[clustering]
mode = master
replication_factor = 2
pass4SymmKey = password123
Which of the following statements describe this Splunk instance? (Select all that apply.)
To activate replication for an index in an indexer cluster, what attribute must be configured in indexes.conf on all peer nodes?
Which of the following use cases would be made possible by multi-site clustering? (select all that apply)
Which server.conf attribute should be added to the master node's server.conf file when decommissioning a site in an indexer cluster?
At which default interval does metrics.log generate a periodic report regarding license utilization?
A Splunk instance has crashed, but no crash log was generated. There is an attempt to determine what user activity caused the crash by running the following search:
What does searching for closed_txn=0 do in this search?
Of the following types of files within an index bucket, which file type may consume the most disk?
The frequency in which a deployment client contacts the deployment server is controlled by what?
A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)
(Which deployer push mode should be used when pushing built-in apps?)
Which of the following tasks should the architect perform when building a deployment plan? (Select all that apply.)
Which of the following would be the least helpful in troubleshooting contents of Splunk configuration files?
Which of the following commands is used to clear the KV store?
Which of the following are client filters available in serverclass.conf? (Select all that apply.)
Which of the following configuration attributes must be set in server, conf on the cluster manager in a single-site indexer cluster?