Consider a use case involving firewall data. There is no Splunk-supported Technical Add-On, but the vendor has built one. What are the items that must be evaluated before installing the add-on? (Select all that apply.)
Which of the following is a valid use case that a search head cluster addresses?
A Splunk architect has inherited the Splunk deployment at Buttercup Games and end users are complaining that the events are inconsistently formatted for a web source. Further investigation reveals that not all weblogs flow through the same infrastructure: some of the data goes through heavy forwarders and some of the forwarders are managed by another department.
Which of the following items might be the cause of this issue?
When troubleshooting monitor inputs, which command checks the status of the tailed files?
What information is needed about the current environment before deploying Splunk? (select all that apply)
How does the average run time of all searches relate to the available CPU cores on the indexers?
By default, what happens to configurations in the local folder of each Splunk app when it is deployed to a search head cluster?
An index has large text log entries with many unique terms in the raw data. Other than the raw data, which index components will take the most space?
A search head cluster with a KV store collection can be updated from where in the KV store collection?
A customer has a four site indexer cluster. The customer has requirements to store five copies of searchable data, with one searchable copy of data at the origin site, and one searchable copy at the disaster recovery site (site4).
Which configuration meets these requirements?
What is needed to ensure that high-velocity sources will not have forwarding delays to the indexers?
Configurations from the deployer are merged into which location on the search head cluster member?
Which of the following would be the least helpful in troubleshooting contents of Splunk configuration files?
How does IT Service Intelligence (ITSI) impact the planning of a Splunk deployment?
Which of the following is a problem that could be investigated using the Search Job Inspector?
Of the following types of files within an index bucket, which file type may consume the most disk?
Which of the following artifacts are included in a Splunk diag file? (Select all that apply.)
(A customer has a Splunk Enterprise deployment and wants to collect data from universal forwarders. What is the best step to secure log traffic?)
When using ingest-based licensing, what Splunk role requires the license manager to scale?
A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)
A customer is migrating 500 Universal Forwarders from an old deployment server to a new deployment server, with a different DNS name. The new deployment server is configured and running.
The old deployment server deployed an app containing an updated deploymentclient.conf file to all forwarders, pointing them to the new deployment server. The app was successfully deployed to all 500 forwarders.
Why would all of the forwarders still be phoning home to the old deployment server?
Which of the following items are important sizing parameters when architecting a Splunk environment? (select all that apply)
In an indexer cluster, what tasks does the cluster manager perform? (select all that apply)
(A customer has an environment with a Search Head Cluster and an indexer cluster. They are troubleshooting license usage data, including indexed volume in bytes per pool, index, host, sourcetype, and source. Where should the license_usage.log file be retrieved from in this environment?)
Which of the following security options must be explicitly configured (i.e. which options are not enabled by default)?
To expand the search head cluster by adding a new member, node2, what first step is required?
Several critical searches that were functioning correctly yesterday are not finding a lookup table today. Which log file would be the best place to start troubleshooting?
What is the algorithm used to determine captaincy in a Splunk search head cluster?
The frequency in which a deployment client contacts the deployment server is controlled by what?
Which of the following statements describe search head clustering? (Select all that apply.)
A customer currently has many deployment clients being managed by a single, dedicated deployment server. The customer plans to double the number of clients.
What could be done to minimize performance issues?
(How can a Splunk admin control the logging level for a specific search to get further debug information?)
If .delta replication fails during knowledge bundle replication, what is the fall-back method for Splunk?
Which of the following configuration attributes must be set in server, conf on the cluster manager in a single-site indexer cluster?
Which of the following will cause the greatest reduction in disk size requirements for a cluster of N indexers running Splunk Enterprise Security?
To reduce the captain's work load in a search head cluster, what setting will prevent scheduled searches from running on the captain?
Data for which of the following indexes will count against an ingest-based license?
A search head has successfully joined a single site indexer cluster. Which command is used to configure the same search head to join another indexer cluster?
Which of the following describe migration from single-site to multisite index replication?
A Splunk instance has the following settings in SPLUNK_HOME/etc/system/local/server.conf:
[clustering]
mode = master
replication_factor = 2
pass4SymmKey = password123
Which of the following statements describe this Splunk instance? (Select all that apply.)
(A new Splunk Enterprise deployment is being architected, and the customer wants to ensure that the data to be indexed is encrypted. Where should TLS be turned on in the Splunk deployment?)
In which phase of the Splunk Enterprise data pipeline are indexed extraction configurations processed?
Users are asking the Splunk administrator to thaw recently-frozen buckets very frequently. What could the Splunk administrator do to reduce the need to thaw buckets?
Which Splunk internal field can confirm duplicate event issues from failed file monitoring?
If there is a deployment server with many clients and one deployment client is not updating apps, which of the following should be done first?
Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)