11.11 Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

SPLK-3002 Exam Dumps - Splunk IT Service Intelligence Certified Admin Exam

Question # 4

Anomaly detection can be enabled on which one of the following?

A.

KPI

B.

Multi-KPI alert

C.

Entity

D.

Service

Full Access
Question # 5

What is an episode?

A.

A workflow task.

B.

A deep dive.

C.

A notable event group.

D.

A notable event.

Full Access
Question # 6

Within a correlation search, dynamic field values can be specified with what syntax?

A.

fieldname

B.

C.

%fieldname%

D.

eval(fieldname)

Full Access
Question # 7

What are valid ITSI Glass Table editor capabilities? (Choose all that apply.)

A.

Creating glass tables.

B.

Correlation search creation.

C.

Service swapping configuration.

D.

Adding KPI metric lanes to glass tables.

Full Access
Question # 8

Which scenario would benefit most by implementing ITSI?

A.

Monitoring of business services functionality.

B.

Monitoring of system hardware.

C.

Monitoring of system process statuses

D.

Monitoring of retail sales metrics.

Full Access
Question # 9

When must a service define entity rules?

A.

If the intention is for the KPIs in the service to filter to only entities assigned to the service.

B.

To enable entity cohesion anomaly detection.

C.

If some or all of the KPIs in the service will be split by entity.

D.

If the intention is for the KPIs in the service to have different aggregate vs. entity KPI values.

Full Access
Question # 10

Where are KPI search results stored?

A.

The default index.

B.

KV Store.

C.

Output to a CSV lookup.

D.

The itsi_summary index.

Full Access
Question # 11

Which of the following accurately describes base searches used for KPIs in a service?

A.

Base searches can be used for multiple services.

B.

A base search can only be used by its service and all dependent services.

C.

All the metrics in a base search are used by one service.

D.

All the KPIs in a service use the same base search.

Full Access
Question # 12

In Episode Review, what is the result of clicking an episode’s Acknowledge button?

A.

Assign the current user as owner.

B.

Change status from New to Acknowledged.

C.

Change status from New to In Progress and assign the current user as owner.

D.

Change status from New to Acknowledged and assign the current user as owner.

Full Access
Question # 13

After ITSI is initially deployed for the operations department at a large company, another department would like to use ITSI but wants to keep their information private from the operations group. How can this be achieved?

A.

Create service templates for each group and create the services from the templates.

B.

Create teams for each department and assign KPIs to each team.

C.

Create services for each group and set the permissions of the services to restrict them to each group.

D.

Create teams for each department and assign services to the teams.

Full Access
Question # 14

Which of the following is a characteristic of base searches?

A.

Search expression, entity splitting rules, and thresholds are configured at the base search level.

B.

It is possible to filter to entities assigned to the service for calculating the metrics for the service’s KPIs.

C.

The fewer KPIs that share a common base search, the more efficiency a base search provides, and anomaly detection is more efficient.

D.

The base search will execute whether or not a KPI needs it.

Full Access
Question # 15

Which glass table feature can be used to toggle displaying KPI values from more than one service on a single widget?

A.

Service templates.

B.

Service dependencies.

C.

Ad-hoc search.

D.

Service swapping.

Full Access
Question # 16

After a notable event has been closed, how long will the meta data for that event remain in the KV Store by default?

A.

6 months.

B.

9 months.

C.

1 year.

D.

3 months.

Full Access
Question # 17

Which of the following best describes a default deep dive?

A.

It initially shows the health scores for all services.

B.

It initially shows the highest importance KPIs.

C.

It initially shows all of the KPIs for a selected service.

D.

It initially shows all the entity swim lanes.

Full Access
Question # 18

What happens when an anomaly is detected?

A.

A separate correlation search needs to be created in order to see it.

B.

A SNMP trap will be sent.

C.

An anomaly alert will appear in core splunk, in index=main.

D.

An anomaly alert will appear as a notable event in Episode Review.

Full Access
Question # 19

Which index contains ITSI Episodes?

A.

itsi_tracked_alerts

B.

itsi_grouped_alerts

C.

itsi_notable_archive

D.

itsi_summary

Full Access
Question # 20

Which of the following best describes an ITSI Glass Table?

A.

A view which displays a system topology overlaid with KPI metrics.

B.

A view which describes a topology.

C.

A dashboard which displays a system topology.

D.

A view showing KPI values in a variety of visual styles.

Full Access
Question # 21

Which capabilities are enabled through “teams”?

A.

Teams allow searches against the itsi_summary index.

B.

Teams restrict notable event alert actions.

C.

Teams restrict searches against the itsi_notable_audit index.

D.

Teams allow restrictions to service content in UI views.

Full Access
Question # 22

Which of the following is a recommended best practice for service and glass table design?

A.

Plan and implement services first, then build detailed glass tables.

B.

Always use the standard icons for glass table widgets to improve portability.

C.

Start with base searches, then services, and then glass tables.

D.

Design glass tables first to discover which KPIs are important.

Full Access
Question # 23

Which of the following actions can be performed with a deep dive?

A.

Create a Multi-KPI alert from the deep dive's current state to warn of similar situations in the future.

B.

Create a predictive analysis model from the deep dive to warn of future service degradation.

C.

Create an anomaly detection alert to show when the same pattern begins in the future.

D.

Create a custom service analyzer from selected deep dive lanes.

Full Access
Question # 24

Which anomaly detection algorithm is included within ITSI?

A.

Entity cohesion

B.

Standard deviation

C.

Linear regression

D.

Infantile regression

Full Access
Question # 25

Which of the following describes a way to delete multiple duplicate entities in ITSI?

A.

Via c CSV upload.

B.

Via the entity lister page.

C.

Via a search using the | deleteentity command.

D.

All of the above.

Full Access
Question # 26

Which of the following is a problem requiring correction in ITSI?

A.

Twoormore entitieswiththe same service ID.

B.

Twoormore entitieswiththe same entity ID.

C.

Twoormore entitieswiththe same value in a single alias field.

D.

Twoormore entitieswiththe same entity key value inanyinfo field.

Full Access
Question # 27

Which deep dive swim lane type does not require writing SPL?

A.

Event lane.

B.

Automatic lane.

C.

Metric lane.

D.

KPI lane.

Full Access