Month End Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Splunk SPLK-3002 Dumps Questions Answers

Page: 1 / 7
Total 96 questions

Splunk IT Service Intelligence Certified Admin Exam Questions and Answers

Question 1

Which of the following is a best practice when configuring maintenance windows?

Options:

A.

Disable any glass tables that reference a KPI that is part of an open maintenance window.

B.

Develop a strategy for configuring a service’s notable event generation when the service’s maintenance window is open.

C.

Give the maintenance window a buffer, for example, 15 minutes before and after actual maintenance work.

D.

Change the color of services and entities that are part of an open maintenance window in the service analyzer.

Buy Now
Question 2

In maintenance mode, which features of KPIs still function?

Options:

A.

KPI searches will execute but will be buffered until the maintenance window is over.

B.

KPI searches still run during maintenance mode, but results go to itsi_maintenance_summary index.

C.

New KPIs can be created, but existing KPIs are locked.

D.

KPI calculations and threshold settings can be modified.

Question 3

Within a correlation search, dynamic field values can be specified with what syntax?

Options:

A.

fieldname

B.

C.

%fieldname%

D.

eval(fieldname)

Question 4

When troubleshooting KPI search performance, which search names in job activity identify base searches?

Options:

A.

Indicator - XXXX - Base Search

B.

Indicator - Shared - xxxx - ITSI Search

C.

Indicator - Base - xxxx - ITSI Search

D.

Indicator - Base - XXXX - Shared Search

Question 5

Which of the following describes a way to delete multiple duplicate entities in ITSI?

Options:

A.

Via c CSV upload.

B.

Via the entity lister page.

C.

Via a search using the | deleteentity command.

D.

All of the above.

Question 6

When a KPI's aggregate value is calculated, which function is called?

Options:

A.

stats

B.

tstats

C.

fieldsummary

D.

eval

Question 7

When creating a custom deep dive, what color are services/KPIs in maintenance mode within the topology view?

Options:

A.

Gray

B.

Purple

C.

Gear Icon

D.

Blue

Question 8

After a notable event has been closed, how long will the meta data for that event remain in the KV Store by default?

Options:

A.

6 months.

B.

9 months.

C.

1 year.

D.

3 months.

Question 9

When must a service define entity rules?

Options:

A.

If the intention is for the KPIs in the service to filter to only entities assigned to the service.

B.

To enable entity cohesion anomaly detection.

C.

If some or all of the KPIs in the service will be split by entity.

D.

If the intention is for the KPIs in the service to have different aggregate vs. entity KPI values.

Question 10

Which of the following items describe ITSI Deep Dive capabilities? (Choose all that apply.)

Options:

A.

Comparing a service’s notable events over a time period.

B.

Visualizing one or more Service KPIs values by time.

C.

Examining and comparing alert levels for KPIs in a service over time.

D.

Comparing swim lane values for a slice of time.

Question 11

When changing a service template, which of the following will be added to linked services by default?

Options:

A.

Thresholds.

B.

Entity Rules.

C.

New KPIs.

D.

Health score.

Question 12

Which of the following items describe ITSI Backup and Restore functionality? (Choose all that apply.)

Options:

A.

A pre-configured default ITSI backup job is provided that can be modified, but not deleted.

B.

ITSI backup is inclusive of KV Store, ITSI Configurations, and index dependencies.

C.

kvstore_to_json.py can be used in scripts or command line to backup ITSI for full or partial backups.

D.

ITSI backups are stored as a collection of JSON formatted files.

Question 13

How can Service Now incidents be created automatically when a Multi-KPI alert triggers? (select all that apply)

Options:

A.

By creating a custom etc/apps/SA-lTOA/workflow_rules. conf

B.

By linking Entities to Service-Now configuration items.

C.

By creating a notable event aggregation policy with a SNOW incident action.

D.

By editing the associated correlation search and specifying an alert action.

Question 14

Which deep dive swim lane type does not require writing SPL?

Options:

A.

Event lane.

B.

Automatic lane.

C.

Metric lane.

D.

KPI lane.

Question 15

Which of the following is an advantage of using adaptive time thresholds?

Options:

A.

Automatically update thresholds daily to manage dynamic changes to KPI values.

B.

Automatically adjust KPI calculation to manage dynamic event data.

C.

Automatically adjust aggregation policy grouping to manage escalating severity.

D.

Automatically adjust correlation search thresholds to adjust sensitivity over time.

Question 16

When working with a notable event group in the Notable Events Review dashboard, which of the following can be set at the individual or group level?

Options:

A.

Service, status, owner.

B.

Severity, status, owner.

C.

Severity, comments, service.

D.

Severity, status, service.

Question 17

Which of the following accurately describes base searches used for KPIs in a service?

Options:

A.

Base searches can be used for multiple services.

B.

A base search can only be used by its service and all dependent services.

C.

All the metrics in a base search are used by one service.

D.

All the KPIs in a service use the same base search.

Question 18

What should be considered when onboarding data into a Splunk index, assuming that ITSI will need to use this data?

Options:

A.

Use | stats functions in custom fields to prepare the data for KPI calculations.

B.

Check if the data could leverage pre-built KPIs from modules, then use the correct TA to onboard the data.

C.

Make sure that all fields conform to CIM, then use the corresponding module to import related services.

D.

Plan to build as many data models as possible for ITSI to leverage

Question 19

Fritz is looking at a Deep Dive with a lane showing the average percent of CPU usage across the four web servers in the web farm. Seeing a spike, he wants to add the graphs of each server on the swim lane, and selects the Lane Overlay Options to do so. No entity overlays are available for the KPI.

What is wrong with his KPI configuration?

Options:

A.

He did not split the KPI by entity.

B.

He did not enable entity filtering.

C.

He configured the KPI to split by pseudo‑entity.

D.

He configured the service with only three entities.

Question 20

When installing ITSI to support a Distributed Search Architecture, which of the following items apply? (Choose all that apply.)

Options:

A.

Copy SA-IndexCreation to all indexers.

B.

Copy SA-IndexCreation to the etc/apps directory on the index cluster master node.

C.

Extract installer package into etc/apps directory of the cluster deployer node.

D.

Extract ITSI app package into etc/apps directory of search head.

Question 21

Which of the following items apply to anomaly detection? (Choose all that apply.)

Options:

A.

Use AD on KPIs that have an unestablished baseline of data points. This allows the ML pattern to perform it’s magic.

B.

A minimum of 24 hours of data is needed for anomaly detection, and a minimum of 4 entities for cohesive analysis.

C.

Anomaly detection automatically generates notable events when KPI data diverges from the pattern.

D.

There are 3 types of anomaly detection supported in ITSI: adhoc, trending, and cohesive.

Question 22

Which of the following is the best use case for configuring a Multi-KPI Alert?

Options:

A.

Comparing content between two notable events.

B.

Using machine learning to evaluate when data falls outside of an expected pattern.

C.

Comparing anomaly detection between two KPIs.

D.

Raising an alert when one or more KPIs indicate an outage is occurring.

Question 23

Which index will contain useful error messages when troubleshooting ITSI issues?

Options:

A.

_introspection

B.

_internal

C.

itsi_summary

D.

itsi_notable_audit

Question 24

Which of the following items describe ITSI teams? (select all that apply)

Options:

A.

Teams should have itoa admin roles added with read-only permissions for services and entities.

B.

Services should be assigned to the 'global' team if all users need access to it.

C.

By default, all services are owned by the built-in 'global' team and administered by the 'itoa_admin' role.

D.

A new team admin role should be created for each team. The new role should inherit the 'itoa_team_admin' role.

Question 25

Which anomaly detection algorithm fulfills the paired monitoring requirement?

Options:

A.

Detection algorithm: Trending anomaly detection

Monitoring requirement: Produce an alert when an entity deviates from its historical behavior.

B.

Detection algorithm: Entity cohesion anomaly detection

Monitoring requirement: Produce an alert when one entity in the KPI is not behaving similar to other entities in the KPI.

C.

Detection algorithm: Trending anomaly detection

Monitoring requirement: Produce an alert when one entity in the KPI is not behaving similar to other entities in the KPI.

D.

Detection algorithm: Entity cohesion anomaly detection

Monitoring requirement: Produce an alert when multiple KPIs in the service deviate from their historical behaviors.

Question 26

Which of the following is a valid type of Multi-KPI Alert?

Options:

A.

Score over composite.

B.

Value over time.

C.

Status over time.

D.

Rise over run.

Question 27

Which of the following is a best practice for identifying the most effective services with which to start an iterative ITSI deployment?

Options:

A.

Only include KPIs if they will be used in multiple services.

B.

Analyze the business to determine the most critical services.

C.

Focus on low-level services.

D.

Define a large number of key services early.

Question 28

In which index are active notable events stored?

Options:

A.

itsi_notable_archive

B.

itsi_notable_audit

C.

itsi_tracked_alerts

D.

itsi_tracked_groups

Page: 1 / 7
Total 96 questions