Configurations from the deployer are merged into which location on the search head cluster member?
In splunkd. log events written to the _internal index, which field identifies the specific log channel?
Which of the following options in limits, conf may provide performance benefits at the forwarding tier?
Which of the following would be the least helpful in troubleshooting contents of Splunk configuration files?
In the deployment planning process, when should a person identify who gets to see network data?
(On which Splunk components does the Splunk App for Enterprise Security place the most load?)
Which command will permanently decommission a peer node operating in an indexer cluster?
In an indexer cluster, what tasks does the cluster manager perform? (select all that apply)
Which tool(s) can be leveraged to diagnose connection problems between an indexer and forwarder? (Select all that apply.)
(A customer creates a saved search that runs on a specific interval. Which internal Splunk log should be viewed to determine if the search ran recently?)
(Which btool command will identify license master configuration errors for a search peer cluster node?)
What does the deployer do in a Search Head Cluster (SHC)? (Select all that apply.)
(A customer has converted a CSV lookup to a KV Store lookup. What must be done to make it available for an automatic lookup?)
Stakeholders have identified high availability for searchable data as their top priority. Which of the following best addresses this requirement?
On search head cluster members, where in $splunk_home does the Splunk Deployer deploy app content by default?
Which of the following statements describe licensing in a clustered Splunk deployment? (Select all that apply.)
(What is the expected performance reduction when architecting Splunk in a virtualized environment instead of a physical environment?)
A Splunk instance has the following settings in SPLUNK_HOME/etc/system/local/server.conf:
[clustering]
mode = master
replication_factor = 2
pass4SymmKey = password123
Which of the following statements describe this Splunk instance? (Select all that apply.)
A monitored log file is changing on the forwarder. However, Splunk searches are not finding any new data that has been added. What are possible causes? (select all that apply)
Which of the following is true regarding Splunk Enterprise's performance? (Select all that apply.)
Which of the following security options must be explicitly configured (i.e. which options are not enabled by default)?
(A customer wishes to keep costs to a minimum, while still implementing Search Head Clustering (SHC). What are the minimum supported architecture standards?)
(What is the best way to configure and manage receiving ports for clustered indexers?)
In search head clustering, which of the following methods can you use to transfer captaincy to a different member? (Select all that apply.)
Which Splunk tool offers a health check for administrators to evaluate the health of their Splunk deployment?
To activate replication for an index in an indexer cluster, what attribute must be configured in indexes.conf on all peer nodes?
How can internal logging levels in a Splunk environment be changed to troubleshoot an issue? (select all that apply)
Which of the following items are important sizing parameters when architecting a Splunk environment? (select all that apply)
(Based on the data sizing and retention parameters listed below, which of the following will correctly calculate the index storage required?)
• Daily rate = 20 GB / day
• Compress factor = 0.5
• Retention period = 30 days
• Padding = 100 GB
What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza?
A customer has a four site indexer cluster. The customer has requirements to store five copies of searchable data, with one searchable copy of data at the origin site, and one searchable copy at the disaster recovery site (site4).
Which configuration meets these requirements?
Users who receive a link to a search are receiving an "Unknown sid" error message when they open the link.
Why is this happening?
Which index-time props.conf attributes impact indexing performance? (Select all that apply.)
A customer currently has many deployment clients being managed by a single, dedicated deployment server. The customer plans to double the number of clients.
What could be done to minimize performance issues?
What is the expected minimum amount of storage required for data across an indexer cluster with the following input and parameters?
• Raw data = 15 GB per day
• Index files = 35 GB per day
• Replication Factor (RF) = 2
• Search Factor (SF) = 2
When troubleshooting a situation where some files within a directory are not being indexed, the ignored files are discovered to have long headers. What is the first thing that should be added to inputs.conf?
A customer has a Search Head Cluster (SHC) with site1 and site2. Site1 has five search heads and Site2 has four. Site1 search heads are preferred captains. What action should be taken on Site2 in a network failure between the sites?
Which of the following configuration attributes must be set in server, conf on the cluster manager in a single-site indexer cluster?
To improve Splunk performance, parallelIngestionPipelines setting can be adjusted on which of the following components in the Splunk architecture? (Select all that apply.)
(A customer has a Splunk Enterprise deployment and wants to collect data from universal forwarders. What is the best step to secure log traffic?)
A three-node search head cluster is skipping a large number of searches across time. What should be done to increase scheduled search capacity on the search head cluster?
When troubleshooting monitor inputs, which command checks the status of the tailed files?
(Which Splunk component allows viewing of the LISPY to assist in debugging Splunk searches?)
Which command should be run to re-sync a stale KV Store member in a search head cluster?
(How can a Splunk admin control the logging level for a specific search to get further debug information?)
What is the algorithm used to determine captaincy in a Splunk search head cluster?
Data for which of the following indexes will count against an ingest-based license?
(If the maxDataSize attribute is set to auto_high_volume in indexes.conf on a 64-bit operating system, what is the maximum hot bucket size?)