What types of files exist in a bucket within a clustered index? (select all that apply)
Which Splunk tool offers a health check for administrators to evaluate the health of their Splunk deployment?
The KV store forms its own cluster within a SHC. What is the maximum number of SHC members KV store will form?
(Based on the data sizing and retention parameters listed below, which of the following will correctly calculate the index storage required?)
• Daily rate = 20 GB / day
• Compress factor = 0.5
• Retention period = 30 days
• Padding = 100 GB
At which default interval does metrics.log generate a periodic report regarding license utilization?
What is the algorithm used to determine captaincy in a Splunk search head cluster?
A Splunk environment collecting 10 TB of data per day has 50 indexers and 5 search heads. A single-site indexer cluster will be implemented. Which of the following is a best practice for added data resiliency?
(An admin removed and re-added search head cluster (SHC) members as part of patching the operating system. When trying to re-add the first member, a script reverted the SHC member to a previous backup, and the member refuses to join the cluster. What is the best approach to fix the member so that it can re-join?)
Which of the following options in limits, conf may provide performance benefits at the forwarding tier?
Splunk configuration parameter settings can differ between multiple .conf files of the same name contained within different apps. Which of the following directories has the highest precedence?
Configurations from the deployer are merged into which location on the search head cluster member?
(Which Splunk component allows viewing of the LISPY to assist in debugging Splunk searches?)
When converting from a single-site to a multi-site cluster, what happens to existing single-site clustered buckets?
How does IT Service Intelligence (ITSI) impact the planning of a Splunk deployment?
Which of the following will cause the greatest reduction in disk size requirements for a cluster of N indexers running Splunk Enterprise Security?
(A customer has a Splunk Enterprise deployment and wants to collect data from universal forwarders. What is the best step to secure log traffic?)
A Splunk instance has crashed, but no crash log was generated. There is an attempt to determine what user activity caused the crash by running the following search:
What does searching for closed_txn=0 do in this search?
A customer has a multisite cluster with site1 and site2 configured. They want to configure search heads in these sites to get search results only from data stored on their local sites. Which step prevents this behavior?
Users who receive a link to a search are receiving an "Unknown sid" error message when they open the link.
Why is this happening?
Which of the following statements describe search head clustering? (Select all that apply.)
(If the maxDataSize attribute is set to auto_high_volume in indexes.conf on a 64-bit operating system, what is the maximum hot bucket size?)
A multi-site indexer cluster can be configured using which of the following? (Select all that apply.)
Which of the following statements describe licensing in a clustered Splunk deployment? (Select all that apply.)
In a distributed environment, knowledge object bundles are replicated from the search head to which location on the search peer(s)?
In an indexer cluster, what tasks does the cluster manager perform? (select all that apply)
Which of the following items are important sizing parameters when architecting a Splunk environment? (select all that apply)
(If a license peer cannot communicate to a license manager for 72 hours or more, what will happen?)
Which of the following use cases would be made possible by multi-site clustering? (select all that apply)
When adding or rejoining a member to a search head cluster, the following error is displayed:
Error pulling configurations from the search head cluster captain; consider performing a destructive configuration resync on this search head cluster member.
What corrective action should be taken?
New data has been added to a monitor input file. However, searches only show older data.
Which splunkd. log channel would help troubleshoot this issue?
Which index-time props.conf attributes impact indexing performance? (Select all that apply.)
Which search head cluster component is responsible for pushing knowledge bundles to search peers, replicating configuration changes to search head cluster members, and scheduling jobs across the search head cluster?
To improve Splunk performance, parallelIngestionPipelines setting can be adjusted on which of the following components in the Splunk architecture? (Select all that apply.)
(Which command is used to initially add a search head to a single-site indexer cluster?)
A customer has a four site indexer cluster. The customer has requirements to store five copies of searchable data, with one searchable copy of data at the origin site, and one searchable copy at the disaster recovery site (site4).
Which configuration meets these requirements?
Which command will permanently decommission a peer node operating in an indexer cluster?
(A customer has converted a CSV lookup to a KV Store lookup. What must be done to make it available for an automatic lookup?)
An indexer cluster is being designed with the following characteristics:
• 10 search peers
• Replication Factor (RF): 4
• Search Factor (SF): 3
• No SmartStore usage
How many search peers can fail before data becomes unsearchable?
Several critical searches that were functioning correctly yesterday are not finding a lookup table today. Which log file would be the best place to start troubleshooting?
A search head cluster member contains the following in its server .conf. What is the Splunk server name of this member?
(What are the possible values for the mode attribute in server.conf for a Splunk server in the [clustering] stanza?)
To reduce the captain's work load in a search head cluster, what setting will prevent scheduled searches from running on the captain?
Consider a use case involving firewall data. There is no Splunk-supported Technical Add-On, but the vendor has built one. What are the items that must be evaluated before installing the add-on? (Select all that apply.)
When Splunk indexes data in a non-clustered environment, what kind of files does it create by default?
Search dashboards in the Monitoring Console indicate that the distributed deployment is approaching its capacity. Which of the following options will provide the most search performance improvement?