New Year Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

SPLK-3002 Splunk IT Service Intelligence Certified Admin Exam Questions and Answers

Questions 4

What should be considered when onboarding data into a Splunk index, assuming that ITSI will need to use this data?

Options:

A.

Use | stats functions in custom fields to prepare the data for KPI calculations.

B.

Check if the data could leverage pre-built KPIs from modules, then use the correct TA to onboard the data.

C.

Make sure that all fields conform to CIM, then use the corresponding module to import related services.

D.

Plan to build as many data models as possible for ITSI to leverage

Buy Now
Questions 5

Which of the following describes entities? (Choose all that apply.)

Options:

A.

Entities must be IT devices, such as routers and switches, and must be identified by either IP value, host name, or mac address.

B.

An abstract (pseudo/logical) entity can be used to split by for a KPI, although no entity rules or filtering can be used to limit data to a specific service.

C.

Multiple entities can share the same alias value, but must have different role values.

D.

To automatically restrict the KPI to only the entities in a particular service, select “Filter to Entities in Service”.

Buy Now
Questions 6

Which views would help an analyst identify that a memory usage KPI is going critical? (select all that apply)

Options:

A.

Memory KPI in a glass table.

B.

Memory panel of the OS Host Details view in the Operating System module.

C.

Memory swim lane in a Deep Dive.

D.

Service & KPI tiles in the Service Analyzer.

Buy Now
Questions 7

Which material would be least useful while planning and designing a service tree for an application team within the company?

Options:

A.

A technical diagram of the application and its interconnections.

B.

An organizational chart of the company.

C.

A report of historical incidents and root cause analysis from the team.

D.

A service topology from an IT Service Management tool.

Buy Now
Questions 8

Which of the following actions can be performed with a deep dive?

Options:

A.

Create a Multi-KPI alert from the deep dive's current state to warn of similar situations in the future.

B.

Create a predictive analysis model from the deep dive to warn of future service degradation.

C.

Create an anomaly detection alert to show when the same pattern begins in the future.

D.

Create a custom service analyzer from selected deep dive lanes.

Buy Now
Questions 9

How can Service Now incidents be created automatically when a Multi-KPI alert triggers? (select all that apply)

Options:

A.

By creating a custom etc/apps/SA-lTOA/workflow_rules. conf

B.

By linking Entities to Service-Now configuration items.

C.

By creating a notable event aggregation policy with a SNOW incident action.

D.

By editing the associated correlation search and specifying an alert action.

Buy Now
Questions 10

Which index is used to store KPI values?

Options:

A.

itsi_summary_metrics

B.

itsi_metrics

C.

itsi_service_health

D.

itsi_summary

Buy Now
Questions 11

Which of the following is a good use case for a Multi-KPI alert?

Options:

A.

Alerting when the values of two or more KPIs go into maintenance mode.

B.

Alerting when the trend of two or more KPIs indicates service failure is imminent.

C.

Alerting when two or more KPIs are deviating from their typical pattern.

D.

Alerting when comparing the values of two or more KPIs indicates an unusual condition is occurring.

Buy Now
Questions 12

How do you automatically restrict a KPI to only the entities in its service, and generate KPI values for each entity?

Options:

A.

Select “Yes” for both “Split by Entity” and “Filter to Entities in Service”.

B.

Select “No” for “Split by Entity” and “Yes” for “Filter to Entities in Service”.

C.

Select “Yes” for “Split by Entity” and “No” for “Filter to Entities in Service”.

D.

Select “No” for both “Split by Entity” and “Filter to Entities in Service”.

Buy Now
Questions 13

After a notable event has been closed, how long will the meta data for that event remain in the KV Store by default?

Options:

A.

6 months.

B.

9 months.

C.

1 year.

D.

3 months.

Buy Now
Questions 14

Which ITSI components are required before a module can be created?

Options:

A.

One or more entity import saved searches.

B.

One or more services with KPIs and their associated base searches.

C.

One or more datamodels.

D.

One or more correlation searches and their associated entities.

Buy Now
Questions 15

To use Adaptive Threshholding, what is the minimum requirement for a set of KPI data?

Options:

A.

14 days old.

B.

7 days old.

C.

30 days old.

D.

10 days old.

Buy Now
Questions 16

Where are KPI search results stored?

Options:

A.

The default index.

B.

KV Store.

C.

Output to a CSV lookup.

D.

The itsi_summary index.

Buy Now
Questions 17

Which of the following statements is accurate when using multiple policies?

Options:

A.

New policies are applied after the default policy.

B.

Policy processing is applied in a defined order.

C.

An event can be processed by only a single policy.

D.

New policies are applied before the default policy.

Buy Now
Questions 18

Which of the following is a best practice for identifying the most effective services with which to start an iterative ITSI deployment?

Options:

A.

Only include KPIs if they will be used in multiple services.

B.

Analyze the business to determine the most critical services.

C.

Focus on low-level services.

D.

Define a large number of key services early.

Buy Now
Questions 19

Which of the following is a best practice when configuring maintenance windows?

Options:

A.

Disable any glass tables that reference a KPI that is part of an open maintenance window.

B.

Develop a strategy for configuring a service’s notable event generation when the service’s maintenance window is open.

C.

Give the maintenance window a buffer, for example, 15 minutes before and after actual maintenance work.

D.

Change the color of services and entities that are part of an open maintenance window in the service analyzer.

Buy Now
Questions 20

Which capabilities are enabled through “teams”?

Options:

A.

Teams allow searches against the itsi_summary index.

B.

Teams restrict notable event alert actions.

C.

Teams restrict searches against the itsi_notable_audit index.

D.

Teams allow restrictions to service content in UI views.

Buy Now
Questions 21

What is the default importance value for dependent services’ health scores?

Options:

A.

11

B.

1

C.

Unassigned

D.

10

Buy Now
Questions 22

Which of the following items apply to anomaly detection? (Choose all that apply.)

Options:

A.

Use AD on KPIs that have an unestablished baseline of data points. This allows the ML pattern to perform it’s magic.

B.

A minimum of 24 hours of data is needed for anomaly detection, and a minimum of 4 entities for cohesive analysis.

C.

Anomaly detection automatically generates notable events when KPI data diverges from the pattern.

D.

There are 3 types of anomaly detection supported in ITSI: adhoc, trending, and cohesive.

Buy Now
Questions 23

In Episode Review, what is the result of clicking an episode’s Acknowledge button?

Options:

A.

Assign the current user as owner.

B.

Change status from New to Acknowledged.

C.

Change status from New to In Progress and assign the current user as owner.

D.

Change status from New to Acknowledged and assign the current user as owner.

Buy Now
Questions 24

Buttercup Retail sells t‑shirts both online and in stores. The IT Operations team is effectively monitoring the digital infrastructure. However, the executive leadership has expressed frustration in understanding what the related business impacts are of IT incidents.

Which of the following entities would give Buttercup Retail executives the most impactful visibility?

Options:

A.

store, product, payment type

B.

store, season, customer age

C.

host, browser type, software version

D.

host, network interface, datacenter

Buy Now
Questions 25

When deploying ITSI on a distributed Splunk installation, which component must be installed on the search head(s)?

Options:

A.

SA-ITOA

B.

ITSI app

C.

All ITSI components

D.

SA-ITSI-Licensechecker

Buy Now
Questions 26

When changing a service template, which of the following will be added to linked services by default?

Options:

A.

Thresholds.

B.

Entity Rules.

C.

New KPIs.

D.

Health score.

Buy Now
Questions 27

For which ITSI function is it a best practice to use a 15-30 minute time buffer?

Options:

A.

Correlation searches.

B.

Adaptive thresholding.

C.

Maintenance windows

D.

Anomaly detection.

Buy Now
Questions 28

Which of the following is a good use case regarding defining entities for a service?

Options:

A.

Automatically associate entities to services using multiple entity aliases.

B.

All of the entities have the same identifying field name.

C.

Being able to split a CPU usage KPI by host name.

D.

KPI total values are aggregated from multiple different category values in the source events.

Buy Now
Exam Code: SPLK-3002
Exam Name: Splunk IT Service Intelligence Certified Admin Exam
Last Update: Dec 16, 2025
Questions: 96

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now SPLK-3002 testing engine

PDF (Q&A)

$43.57  $124.49
buy now SPLK-3002 pdf