Winter Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

SPLK-2002 Exam Dumps - Splunk Enterprise Certified Architect

Go to page:
Question # 41

Which Splunk internal index contains license-related events?

A.

_audit

B.

_license

C.

_internal

D.

_introspection

Full Access
Question # 42

Which of the following statements describe licensing in a clustered Splunk deployment? (Select all that apply.)

A.

Free licenses do not support clustering.

B.

Replicated data does not count against licensing.

C.

Each cluster member requires its own clustering license.

D.

Cluster members must share the same license pool and license master.

Full Access
Question # 43

A search head cluster with a KV store collection can be updated from where in the KV store collection?

A.

The search head cluster captain.

B.

The KV store primary search head.

C.

Any search head except the captain.

D.

Any search head in the cluster.

Full Access
Question # 44

What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza?

A.

btool.log

B.

metrics.log

C.

splunkd.log

D.

tailing_processor.log

Full Access
Question # 45

Which of the following security options must be explicitly configured (i.e. which options are not enabled by default)?

A.

Data encryption between Splunk Web and splunkd.

B.

Certificate authentication between forwarders and indexers.

C.

Certificate authentication between Splunk Web and search head.

D.

Data encryption for distributed search between search heads and indexers.

Full Access
Question # 46

How does the average run time of all searches relate to the available CPU cores on the indexers?

A.

Average run time is independent of the number of CPU cores on the indexers.

B.

Average run time decreases as the number of CPU cores on the indexers decreases.

C.

Average run time increases as the number of CPU cores on the indexers decreases.

D.

Average run time increases as the number of CPU cores on the indexers increases.

Full Access
Question # 47

A Splunk instance has crashed, but no crash log was generated. There is an attempt to determine what user activity caused the crash by running the following search:

What does searching for closed_txn=0 do in this search?

A.

Filters results to situations where Splunk was started and stopped multiple times.

B.

Filters results to situations where Splunk was started and stopped once.

C.

Filters results to situations where Splunk was stopped and then immediately restarted.

D.

Filters results to situations where Splunk was started, but not stopped.

Full Access
Question # 48

Several critical searches that were functioning correctly yesterday are not finding a lookup table today. Which log file would be the best place to start troubleshooting?

A.

btool.log

B.

web_access.log

C.

health.log

D.

configuration_change.log

Full Access
Go to page: