Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

How does Monitoring Console (MC) initially identify the server role(s) of a new Splunk Instance?

A.

The MC uses a REST endpoint to query the server.

B.

Roles are manually assigned within the MC.

C.

Roles are read from distsearch.conf.

D.

The MC assigns all possible roles by default.

Which of the following server roles should be configured for a host which indexes its internal logs locally?

A.

Cluster master

B.

Indexer

C.

Monitoring Console (MC)

D.

Search head

A customer has been using Splunk for one year, utilizing a single/all-in-one instance. This single Splunk server is now struggling to cope with the daily ingest rate. Also, Splunk has become a vital system in day-to-day operations making high availability a consideration for the Splunk service. The customer is unsure how to design the new environment topology in order to provide this.

Which resource would help the customer gather the requirements for their new architecture?

A.

Direct the customer to the docs.splunk.com and tell them that all the information to help them select the right design is documented there.

B.

Ask the customer to engage with the sales team immediately as they probably need a larger license.

C.

Refer the customer to answers.splunk.com as someone else has probably already designed a system that meets their requirements.

D.

Refer the customer to the Splunk Validated Architectures document in order to guide them through which approved architectures could meet their requirements.

In preparation for the deployment of a new environment for a customer, which of the following mappings are correct per PS best practices?

A.

Option A

B.

Option B

C.

Option C

D.

Option D

A customer has a search cluster (SHC) of six members split evenly between two data centers (DC). The customer is concerned with network connectivity between the two DCs due to frequent outages. Which of the following is true as it relates to SHC resiliency when a network outage occurs between the two DCs?

A.

The SHC will function as expected as the SHC deployer will become the new captain until the network communication is restored.

B.

The SHC will stop all scheduled search activity within the SHC.

C.

The SHC will function as expected as the minimum required number of nodes for a SHC is 3.

D.

The SHC will function as expected as the SHC captain will fall back to previous active captain in the remaining site.

Which configuration item should be set to false to significantly improve data ingestion performance?

A.

AUTO_KV_JSON

B.

BREAK_ONLY_BEFORE_DATE

C.

SHOULD_LINEMERGE

D.

ANNOTATE_PUNCT

A customer is using regex to whitelist access logs and secure logs from a web server, but only the access logs are being ingested. Which troubleshooting resource would provide insight into why the secure logs are not being ingested?

A.

list monitor

B.

oneshot

C.

btprobe

D.

tailingprocessor

Report acceleration has been enabled for a specific use case. In which bucket location is the corresponding CSV file located?

A.

thawedPath

B.

summaryHomePath

C.

tstatsHomePath

D.

homePath, coldPath

What is the primary driver behind implementing indexer clustering in a customer’s environment?

A.

To improve resiliency as the search load increases.

B.

To reduce indexing latency.

C.

To scale out a Splunk environment to offer higher performance capability.

D.

To provide higher availability for buckets of data.

Which statement is true about sub searches?

A.

Sub searches are faster than other types of searches.

B.

Sub searches work best for joining two large result sets.

C.

Sub searches run at the same time as their outer search.

D.

Sub searches work best for small result sets.