Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: geek65

SPLK-2002 Splunk Enterprise Certified Architect Questions and Answers

Questions 4

In search head clustering, which of the following methods can you use to transfer captaincy to a different member? (Select all that apply.)

Options:

A.

Use the Monitoring Console.

B.

Use the Search Head Clustering settings menu from Splunk Web on any member.

C.

Run the splunk transfer shcluster-captain command from the current captain.

D.

Run the splunk transfer shcluster-captain command from the member you would like to become the captain.

Buy Now
Questions 5

Before users can use a KV store, an admin must create a collection. Where is a collection is defined?

Options:

A.

kvstore.conf

B.

collection.conf

C.

collections.conf

D.

kvcollections.conf

Buy Now
Questions 6

(If the maxDataSize attribute is set to auto_high_volume in indexes.conf on a 64-bit operating system, what is the maximum hot bucket size?)

Options:

A.

4 GB

B.

750 MB

C.

10 GB

D.

1 GB

Buy Now
Questions 7

metrics. log is stored in which index?

Options:

A.

main

B.

_telemetry

C.

_internal

D.

_introspection

Buy Now
Questions 8

A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)

Options:

A.

The field was extracted as a private knowledge object.

B.

The events are tagged as communicate, but are missing the network tag.

C.

The Typing Queue, which does regular expression replacements, is blocked.

D.

The colleague did not explicitly use the field in the search and the search was set to Fast Mode.

Buy Now
Questions 9

Which of the following options can improve reliability of syslog delivery to Splunk? (Select all that apply.)

Options:

A.

Use TCP syslog.

B.

Configure UDP inputs on each Splunk indexer to receive data directly.

C.

Use a network load balancer to direct syslog traffic to active backend syslog listeners.

D.

Use one or more syslog servers to persist data with a Universal Forwarder to send the data to Splunk indexers.

Buy Now
Questions 10

Which of the following is true for indexer cluster knowledge bundles?

Options:

A.

Only app-name/local is pushed.

B.

app-name/default and app-name/local are merged before pushing.

C.

Only app-name/default is pushed.

D.

app-name/default and app-name/local are pushed without change.

Buy Now
Questions 11

Where in the Job Inspector can details be found to help determine where performance is affected?

Options:

A.

Search Job Properties > runDuration

B.

Search Job Properties > runtime

C.

Job Details Dashboard > Total Events Matched

D.

Execution Costs > Components

Buy Now
Questions 12

In splunkd. log events written to the _internal index, which field identifies the specific log channel?

Options:

A.

component

B.

source

C.

sourcetype

D.

channel

Buy Now
Questions 13

(A high-volume source and a low-volume source feed into the same index. Which of the following items best describe the impact of this design choice?)

Options:

A.

Low volume data will improve the compression factor of the high volume data.

B.

Search speed on low volume data will be slower than necessary.

C.

Low volume data may move out of the index based on volume rather than age.

D.

High volume data is optimized by the presence of low volume data.

Buy Now
Questions 14

When troubleshooting monitor inputs, which command checks the status of the tailed files?

Options:

A.

splunk cmd btool inputs list | tail

B.

splunk cmd btool check inputs layer

C.

curl https://serverhost:8089/services/admin/inputstatus/TailingProcessor:FileStatus

D.

curl https://serverhost:8089/services/admin/inputstatus/TailingProcessor:Tailstatus

Buy Now
Questions 15

A new Splunk customer is using syslog to collect data from their network devices on port 514. What is the best practice for ingesting this data into Splunk?

Options:

A.

Configure syslog to send the data to multiple Splunk indexers.

B.

Use a Splunk indexer to collect a network input on port 514 directly.

C.

Use a Splunk forwarder to collect the input on port 514 and forward the data.

D.

Configure syslog to write logs and use a Splunk forwarder to collect the logs.

Buy Now
Questions 16

What does the deployer do in a Search Head Cluster (SHC)? (Select all that apply.)

Options:

A.

Distributes apps to SHC members.

B.

Bootstraps a clean Splunk install for a SHC.

C.

Distributes non-search-related and manual configuration file changes.

D.

Distributes runtime knowledge object changes made by users across the SHC.

Buy Now
Questions 17

(A customer has a Splunk Enterprise deployment and wants to collect data from universal forwarders. What is the best step to secure log traffic?)

Options:

A.

Create signed SSL certificates and use them to encrypt data between the forwarders and indexers.

B.

Use the Splunk provided SSL certificates to encrypt data between the forwarders and indexers.

C.

Ensure all forwarder traffic is routed through a web application firewall (WAF).

D.

Create signed SSL certificates and use them to encrypt data between the search heads and indexers.

Buy Now
Questions 18

(Which deployer push mode should be used when pushing built-in apps?)

Options:

A.

merge_to_default

B.

local_only

C.

full

D.

default only

Buy Now
Questions 19

Of the following types of files within an index bucket, which file type may consume the most disk?

Options:

A.

Rawdata

B.

Bloom filter

C.

Metadata (.data)

D.

Inverted index (.tsidx)

Buy Now
Questions 20

In the deployment planning process, when should a person identify who gets to see network data?

Options:

A.

Deployment schedule

B.

Topology diagramming

C.

Data source inventory

D.

Data policy definition

Buy Now
Questions 21

(A customer has converted a CSV lookup to a KV Store lookup. What must be done to make it available for an automatic lookup?)

Options:

A.

Add the repFactor=true attribute in collections.conf.

B.

Add the replicate=true attribute in lookups.conf.

C.

Add the replicate=true attribute in collections.conf.

D.

Add the repFactor=true attribute in lookups.conf.

Buy Now
Questions 22

When using the props.conf LINE_BREAKER attribute to delimit multi-line events, the SHOULD_LINEMERGE attribute should be set to what?

Options:

A.

Auto

B.

None

C.

True

D.

False

Buy Now
Questions 23

Consider a use case involving firewall data. There is no Splunk-supported Technical Add-On, but the vendor has built one. What are the items that must be evaluated before installing the add-on? (Select all that apply.)

Options:

A.

Identify number of scheduled or real-time searches.

B.

Validate if this Technical Add-On enables event data for a data model.

C.

Identify the maximum number of forwarders Technical Add-On can support.

D.

Verify if Technical Add-On needs to be installed onto both a search head or indexer.

Buy Now
Questions 24

Which of the following tasks should the architect perform when building a deployment plan? (Select all that apply.)

Options:

A.

Use case checklist.

B.

Install Splunk apps.

C.

Inventory data sources.

D.

Review network topology.

Buy Now
Questions 25

Which of the following can a Splunk diag contain?

Options:

A.

Search history, Splunk users and their roles, running processes, indexed data

B.

Server specs, current open connections, internal Splunk log files, index listings

C.

KV store listings, internal Splunk log files, search peer bundles listings, indexed data

D.

Splunk platform configuration details, Splunk users and their roles, current open connections, index listings

Buy Now
Questions 26

How does IT Service Intelligence (ITSI) impact the planning of a Splunk deployment?

Options:

A.

ITSI requires a dedicated deployment server.

B.

The amount of users using ITSI will not impact performance.

C.

ITSI in a Splunk deployment does not require additional hardware resources.

D.

Depending on the Key Performance Indicators that are being tracked, additional infrastructure may be needed.

Buy Now
Questions 27

Splunk Enterprise platform instrumentation refers to data that the Splunk Enterprise deployment logs in the _introspection index. Which of the following logs are included in this index? (Select all that apply.)

Options:

A.

audit.log

B.

metrics.log

C.

disk_objects.log

D.

resource_usage.log

Buy Now
Questions 28

A Splunk architect has inherited the Splunk deployment at Buttercup Games and end users are complaining that the events are inconsistently formatted for a web source. Further investigation reveals that not all weblogs flow through the same infrastructure: some of the data goes through heavy forwarders and some of the forwarders are managed by another department.

Which of the following items might be the cause of this issue?

Options:

A.

The search head may have different configurations than the indexers.

B.

The data inputs are not properly configured across all the forwarders.

C.

The indexers may have different configurations than the heavy forwarders.

D.

The forwarders managed by the other department are an older version than the rest.

Buy Now
Questions 29

Which Splunk tool offers a health check for administrators to evaluate the health of their Splunk deployment?

Options:

A.

btool

B.

DiagGen

C.

SPL Clinic

D.

Monitoring Console

Buy Now
Questions 30

(Which of the following is a valid way to determine if a new bundle push will trigger a rolling restart?)

Options:

A.

splunk show cluster-bundle-status

B.

splunk apply cluster-bundle

C.

splunk validate cluster-bundle —check-restart

D.

splunk apply cluster-bundle —validate-bundle

Buy Now
Questions 31

(Which index does Splunk use to record user activities?)

Options:

A.

_internal

B.

_audit

C.

_kvstore

D.

_telemetry

Buy Now
Questions 32

At which default interval does metrics.log generate a periodic report regarding license utilization?

Options:

A.

10 seconds

B.

30 seconds

C.

60 seconds

D.

300 seconds

Buy Now
Questions 33

When should a Universal Forwarder be used instead of a Heavy Forwarder?

Options:

A.

When most of the data requires masking.

B.

When there is a high-velocity data source.

C.

When data comes directly from a database server.

D.

When a modular input is needed.

Buy Now
Questions 34

To expand the search head cluster by adding a new member, node2, what first step is required?

Options:

A.

splunk bootstrap shcluster-config -mgmt_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

B.

splunk init shcluster-config -master_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

C.

splunk init shcluster-config -mgmt_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

D.

splunk add shcluster-member -new_member_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

Buy Now
Questions 35

When adding or decommissioning a member from a Search Head Cluster (SHC), what is the proper order of operations?

Options:

A.

1. Delete Splunk Enterprise, if it exists.2. Install and initialize the instance.3. Join the SHC.

B.

1. Install and initialize the instance.2. Delete Splunk Enterprise, if it exists.3. Join the SHC.

C.

1. Initialize cluster rebalance operation.2. Remove master node from cluster.3. Trigger replication.

D.

1. Trigger replication.2. Remove master node from cluster.3. Initialize cluster rebalance operation.

Buy Now
Questions 36

Which of the following would be the least helpful in troubleshooting contents of Splunk configuration files?

Options:

A.

crash logs

B.

search.log

C.

btool output

D.

diagnostic logs

Buy Now
Questions 37

How does the average run time of all searches relate to the available CPU cores on the indexers?

Options:

A.

Average run time is independent of the number of CPU cores on the indexers.

B.

Average run time decreases as the number of CPU cores on the indexers decreases.

C.

Average run time increases as the number of CPU cores on the indexers decreases.

D.

Average run time increases as the number of CPU cores on the indexers increases.

Buy Now
Questions 38

Splunk Enterprise performs a cyclic redundancy check (CRC) against the first and last bytes to prevent the same file from being re-indexed if it is rotated or renamed. What is the number of bytes sampled by default?

Options:

A.

128

B.

512

C.

256

D.

64

Buy Now
Questions 39

What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza?

Options:

A.

btool.log

B.

metrics.log

C.

splunkd.log

D.

tailing_processor.log

Buy Now
Questions 40

(Which of the following data sources are used for the Monitoring Console dashboards?)

Options:

A.

REST API calls

B.

Splunk btool

C.

Splunk diag

D.

metrics.log

Buy Now
Questions 41

A three-node search head cluster is skipping a large number of searches across time. What should be done to increase scheduled search capacity on the search head cluster?

Options:

A.

Create a job server on the cluster.

B.

Add another search head to the cluster.

C.

server.conf captain_is_adhoc_searchhead = true.

D.

Change limits.conf value for max_searches_per_cpu to a higher value.

Buy Now
Questions 42

In a distributed environment, knowledge object bundles are replicated from the search head to which location on the search peer(s)?

Options:

A.

SPLUNK_HOME/var/lib/searchpeers

B.

SPLUNK_HOME/var/log/searchpeers

C.

SPLUNK_HOME/var/run/searchpeers

D.

SPLUNK_HOME/var/spool/searchpeers

Buy Now
Questions 43

Which Splunk server role regulates the functioning of indexer cluster?

Options:

A.

Indexer

B.

Deployer

C.

Master Node

D.

Monitoring Console

Buy Now
Questions 44

Which of the following should be included in a deployment plan?

Options:

A.

Business continuity and disaster recovery plans.

B.

Current logging details and data source inventory.

C.

Current and future topology diagrams of the IT environment.

D.

A comprehensive list of stakeholders, either direct or indirect.

Buy Now
Questions 45

Which of the following statements about integrating with third-party systems is true? (Select all that apply.)

Options:

A.

A Hadoop application can search data in Splunk.

B.

Splunk can search data in the Hadoop File System (HDFS).

C.

You can use Splunk alerts to provision actions on a third-party system.

D.

You can forward data from Splunk forwarder to a third-party system without indexing it first.

Buy Now
Questions 46

Which Splunk Enterprise offering has its own license?

Options:

A.

Splunk Cloud Forwarder

B.

Splunk Heavy Forwarder

C.

Splunk Universal Forwarder

D.

Splunk Forwarder Management

Buy Now
Questions 47

Which of the following are client filters available in serverclass.conf? (Select all that apply.)

Options:

A.

DNS name.

B.

IP address.

C.

Splunk server role.

D.

Platform (machine type).

Buy Now
Questions 48

(Which Splunk component allows viewing of the LISPY to assist in debugging Splunk searches?)

Options:

A.

dbinspect

B.

Monitoring Console

C.

walklex

D.

Search Job Inspector

Buy Now
Questions 49

Which of the following is an indexer clustering requirement?

Options:

A.

Must use shared storage.

B.

Must reside on a dedicated rack.

C.

Must have at least three members.

D.

Must share the same license pool.

Buy Now
Questions 50

What is the minimum reference server specification for a Splunk indexer?

Options:

A.

12 CPU cores, 12GB RAM, 800 IOPS

B.

16 CPU cores, 16GB RAM, 800 IOPS

C.

24 CPU cores, 16GB RAM, 1200 IOPS

D.

28 CPU cores, 32GB RAM, 1200 IOPS

Buy Now
Questions 51

Which of the following is a problem that could be investigated using the Search Job Inspector?

Options:

A.

Error messages are appearing underneath the search bar in Splunk Web.

B.

Dashboard panels are showing "Waiting for queued job to start" on page load.

C.

Different users are seeing different extracted fields from the same search.

D.

Events are not being sorted in reverse chronological order.

Buy Now
Questions 52

Which of the following statements describe search head clustering? (Select all that apply.)

Options:

A.

A deployer is required.

B.

At least three search heads are needed.

C.

Search heads must meet the high-performance reference server requirements.

D.

The deployer must have sufficient CPU and network resources to process service requests and push configurations.

Buy Now
Questions 53

Which of the following is true regarding Splunk Enterprise's performance? (Select all that apply.)

Options:

A.

Adding search peers increases the maximum size of search results.

B.

Adding RAM to existing search heads provides additional search capacity.

C.

Adding search peers increases the search throughput as the search load increases.

D.

Adding search heads provides additional CPU cores to run more concurrent searches.

Buy Now
Questions 54

Which tool(s) can be leveraged to diagnose connection problems between an indexer and forwarder? (Select all that apply.)

Options:

A.

telnet

B.

tcpdump

C.

splunk btool

D.

splunk btprobe

Buy Now
Questions 55

Which of the following commands is used to clear the KV store?

Options:

A.

splunk clean kvstore

B.

splunk clear kvstore

C.

splunk delete kvstore

D.

splunk reinitialize kvstore

Buy Now
Questions 56

What is needed to ensure that high-velocity sources will not have forwarding delays to the indexers?

Options:

A.

Increase the default value of sessionTimeout in server, conf.

B.

Increase the default limit for maxKBps in limits.conf.

C.

Decrease the value of forceTimebasedAutoLB in outputs. conf.

D.

Decrease the default value of phoneHomelntervallnSecs in deploymentclient .conf.

Buy Now
Questions 57

When adding or rejoining a member to a search head cluster, the following error is displayed:

Error pulling configurations from the search head cluster captain; consider performing a destructive configuration resync on this search head cluster member.

What corrective action should be taken?

Options:

A.

Restart the search head.

B.

Run the splunk apply shcluster-bundle command from the deployer.

C.

Run the clean raft command on all members of the search head cluster.

D.

Run the splunk resync shcluster-replicated-config command on this member.

Buy Now
Questions 58

(Which of the following is a benefit of using SmartStore?)

Options:

A.

Automatic selection of replication and search factors.

B.

Separating storage from compute.

C.

Knowledge Object replication.

D.

Cluster Manager is no longer required.

Buy Now
Questions 59

Because Splunk indexing is read/write intensive, it is important to select the appropriate disk storage solution for each deployment. Which of the following statements is accurate about disk storage?

Options:

A.

High performance SAN should never be used.

B.

Enable NFS for storing hot and warm buckets.

C.

The recommended RAID setup is RAID 10 (1 + 0).

D.

Virtualized environments are usually preferred over bare metal for Splunk indexers.

Buy Now
Exam Code: SPLK-2002
Exam Name: Splunk Enterprise Certified Architect
Last Update: Nov 18, 2025
Questions: 197
SPLK-2002 pdf

SPLK-2002 PDF

$29.75  $84.99
SPLK-2002 Engine

SPLK-2002 Testing Engine

$35  $99.99
SPLK-2002 PDF + Engine

SPLK-2002 PDF + Testing Engine

$47.25  $134.99