Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

SPLK-3002 Splunk IT Service Intelligence Certified Admin Exam Questions and Answers

Questions 4

Which of the following is the best use case for configuring a Multi-KPI Alert?

Options:

A.

Comparing content between two notable events.

B.

Using machine learning to evaluate when data falls outside of an expected pattern.

C.

Comparing anomaly detection between two KPIs.

D.

Raising an alert when one or more KPIs indicate an outage is occurring.

Buy Now
Questions 5

For which ITSI function is it a best practice to use a 15-30 minute time buffer?

Options:

A.

Correlation searches.

B.

Adaptive thresholding.

C.

Maintenance windows

D.

Anomaly detection.

Buy Now
Questions 6

How should entities be handled during the data audit phase of requirements gathering?

Options:

A.

Entity meta-data for info and aliases should be identified and recorded as requirements.

B.

Entities should be noted based upon Service KPI requirements such as 'by host' or 'by product line'.

C.

Entities must be identified for every Service KPI defined and recorded in requirements.

D.

Entities identified should be included in the entity filtering requirements, such as 'by processld' or 'by host'.

Buy Now
Questions 7

Which of the following are deployment recommendations for ITSI? (Choose all that apply.)

Options:

A.

Deployments often require an increase of hardware resources above base Splunk requirements.

B.

Deployments require a dedicated ITSI search head.

C.

Deployments may increase the number of required indexers based on the number of KPI searches.

D.

Deployments should use fastest possible disk arrays for indexers.

Buy Now
Questions 8

Which of the following actions can be performed with a deep dive?

Options:

A.

Create a Multi-KPI alert from the deep dive's current state to warn of similar situations in the future.

B.

Create a predictive analysis model from the deep dive to warn of future service degradation.

C.

Create an anomaly detection alert to show when the same pattern begins in the future.

D.

Create a custom service analyzer from selected deep dive lanes.

Buy Now
Questions 9

There are two Smart Mode configuration settings that control how fields affect grouping. Which of these is correct?

Options:

A.

Text deviation and category deviation.

B.

Text similarity and category deviation.

C.

Text similarity and category similarity.

D.

Text deviation and category similarity.

Buy Now
Questions 10

What is the main purpose of the service analyzer?

Options:

A.

Display a list of All Services and Entities.

B.

Trigger external alerts based on threshold violations.

C.

Allow Analysts to add comments to Alerts.

D.

Monitor overall Service and KPI status.

Buy Now
Questions 11

Which of the following is a recommended best practice for ITSI installation?

Options:

A.

ITSI should not be installed on search heads that have Enterprise Security installed.

B.

Before installing ITSI, make sure the Common Information Model (CIM) is installed.

C.

Install the Machine Learning Toolkit app if anomaly detection must be configured.

D.

Install ITSI on one search head in a search head cluster and migrate the configuration bundle to other search heads.

Buy Now
Questions 12

Which of the following accurately describes base searches used for KPIs in a service?

Options:

A.

Base searches can be used for multiple services.

B.

A base search can only be used by its service and all dependent services.

C.

All the metrics in a base search are used by one service.

D.

All the KPIs in a service use the same base search.

Buy Now
Questions 13

Anomaly detection can be enabled on which one of the following?

Options:

A.

KPI

B.

Multi-KPI alert

C.

Entity

D.

Service

Buy Now
Questions 14

There are two departments using ITSI. Finance and Sales. Analysts in each department should not be allowed to see each other’s services. What are the role configuration steps required to accomplish this?

Options:

A.

itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_analyst.

B.

itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_team_analyst; itoa_sales_analyst, inherited from itoa_team_analyst.

C.

itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_team_analyst.

D.

itoa_finance_admin, inherited from itoa_team_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_analyst.

Buy Now
Questions 15

Which of the following is a valid type of Multi-KPI Alert?

Options:

A.

Score over composite.

B.

Value over time.

C.

Status over time.

D.

Rise over run.

Buy Now
Questions 16

Which index contains ITSI Episodes?

Options:

A.

itsi_tracked_alerts

B.

itsi_grouped_alerts

C.

itsi_notable_archive

D.

itsi_summary

Buy Now
Questions 17

When in maintenance mode, which of the following is accurate?

Options:

A.

Once the window is over, KPIs and notable events will begin to be generated again.

B.

KPIs are shown in blue while in maintenance mode.

C.

Maintenance mode slots are scheduled on a per hour basis.

D.

Service health scores and KPI events are deleted until the window is over.

Buy Now
Questions 18

Which scenario would benefit most by implementing ITSI?

Options:

A.

Monitoring of business services functionality.

B.

Monitoring of system hardware.

C.

Monitoring of system process statuses

D.

Monitoring of retail sales metrics.

Buy Now
Questions 19

Which of the following are characteristics of ITSI service dependencies? (select all that apply)

Options:

A.

If a primary service has a dependent service KPI and the KPI's importance level is changed, the dependency is broken.

B.

It is best practice to use the dependent service's built-in 'ServiceHealthScore' KPI to reflect impact to the primary service.

C.

Setting the dependent service KPI importance level will be treated as any other KPI in the primary service's health score.

D.

Impactful dependent services should only be configured to one primary service to avoid false negatives in Multi KPI Alerts.

Buy Now
Questions 20

Which of the following is a characteristic of base searches?

Options:

A.

Search expression, entity splitting rules, and thresholds are configured at the base search level.

B.

It is possible to filter to entities assigned to the service for calculating the metrics for the service’s KPIs.

C.

The fewer KPIs that share a common base search, the more efficiency a base search provides, and anomaly detection is more efficient.

D.

The base search will execute whether or not a KPI needs it.

Buy Now
Questions 21

Which of the following services often has KPIs but no entities?

Options:

A.

Security Service.

B.

Network Service.

C.

Business Service.

D.

Technical Service.

Buy Now
Questions 22

Which of the following describes default deep dives?

Options:

A.

Are manually generated and can be accessed via the Service Analyzer.

B.

Include all KPIs of all services.

C.

Are auto-generated and can be accessed via the Service Analyzer.

D.

Include health scores of all services.

Buy Now
Questions 23

Which is the least permissive role required to modify default deep dives?

Options:

A.

itoa_analyst

B.

admin

C.

power

D.

itoa_admin

Buy Now
Questions 24

Which of the following statements describe default glass tables in ITSI?

Options:

A.

The Service Health Score default glass table.

B.

There is one default glass table per service.

C.

There is one service template default glass table.

D.

There are no default glass tables.

Buy Now
Questions 25

Which of the following items describe ITSI Deep Dive capabilities? (Choose all that apply.)

Options:

A.

Comparing a service’s notable events over a time period.

B.

Visualizing one or more Service KPIs values by time.

C.

Examining and comparing alert levels for KPIs in a service over time.

D.

Comparing swim lane values for a slice of time.

Buy Now
Questions 26

Which of the following is an advantage of using adaptive time thresholds?

Options:

A.

Automatically update thresholds daily to manage dynamic changes to KPI values.

B.

Automatically adjust KPI calculation to manage dynamic event data.

C.

Automatically adjust aggregation policy grouping to manage escalating severity.

D.

Automatically adjust correlation search thresholds to adjust sensitivity over time.

Buy Now
Questions 27

To use Adaptive Threshholding, what is the minimum requirement for a set of KPI data?

Options:

A.

14 days old.

B.

7 days old.

C.

30 days old.

D.

10 days old.

Buy Now
Questions 28

Which of the following is a good use case for creating a custom module?

Options:

A.

Modules are required to create entity and service import searches.

B.

Modules are required to be able to create custom visualizations for deep dives.

C.

Making it easy to migrate KPI base searches and related visualizations to other ITSI installations.

D.

Creating a service template to make it easy to automatically create new services during service and entity import.

Buy Now
Exam Code: SPLK-3002
Exam Name: Splunk IT Service Intelligence Certified Admin Exam
Last Update: May 15, 2026
Questions: 96

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now SPLK-3002 testing engine

PDF (Q&A)

$43.57  $124.49
buy now SPLK-3002 pdf