(Where can files be placed in a configuration bundle on a search peer that will persist after a new configuration bundle has been deployed?)
(A customer creates a saved search that runs on a specific interval. Which internal Splunk log should be viewed to determine if the search ran recently?)
When preparing to ingest a new data source, which of the following is optional in the data source assessment?
In splunkd. log events written to the _internal index, which field identifies the specific log channel?
Consider a use case involving firewall data. There is no Splunk-supported Technical Add-On, but the vendor has built one. What are the items that must be evaluated before installing the add-on? (Select all that apply.)
A search head cluster member contains the following in its server .conf. What is the Splunk server name of this member?
(Which of the following is a minimum search head specification for a distributed Splunk environment?)
A customer plans to ingest 600 GB of data per day into Splunk. They will have six concurrent users, and they also want high data availability and high search performance. The customer is concerned about cost and wants to spend the minimum amount on the hardware for Splunk. How many indexers are recommended for this deployment?
(A new Splunk Enterprise deployment is being architected, and the customer wants to ensure that the data to be indexed is encrypted. Where should TLS be turned on in the Splunk deployment?)
Which of the following will cause the greatest reduction in disk size requirements for a cluster of N indexers running Splunk Enterprise Security?
A Splunk deployment is being architected and the customer will be using Splunk Enterprise Security (ES) and Splunk IT Service Intelligence (ITSI). Through data onboarding and sizing, it is determined that over 200 discrete KPIs will be tracked by ITSI and 1TB of data per day by ES. What topology ensures a scalable and performant deployment?
Which of the following clarification steps should be taken if apps are not appearing on a deployment client? (Select all that apply.)
Which of the following is a valid use case that a search head cluster addresses?
Users who receive a link to a search are receiving an "Unknown sid" error message when they open the link.
Why is this happening?
(It is possible to lose UI edit functionality after manually editing which of the following files in the deployment server?)
(What are the possible values for the mode attribute in server.conf for a Splunk server in the [clustering] stanza?)
When using the props.conf LINE_BREAKER attribute to delimit multi-line events, the SHOULD_LINEMERGE attribute should be set to what?
Which of the following use cases would be made possible by multi-site clustering? (select all that apply)
In which phase of the Splunk Enterprise data pipeline are indexed extraction configurations processed?
The master node distributes configuration bundles to peer nodes. Which directory peer nodes receive the bundles?
To improve Splunk performance, parallelIngestionPipelines setting can be adjusted on which of the following components in the Splunk architecture? (Select all that apply.)
Which server.conf attribute should be added to the master node's server.conf file when decommissioning a site in an indexer cluster?
When Splunk indexes data in a non-clustered environment, what kind of files does it create by default?
Which of the following is true regarding Splunk Enterprise's performance? (Select all that apply.)
(Which Splunk component allows viewing of the LISPY to assist in debugging Splunk searches?)
When troubleshooting a situation where some files within a directory are not being indexed, the ignored files are discovered to have long headers. What is the first thing that should be added to inputs.conf?
When adding or decommissioning a member from a Search Head Cluster (SHC), what is the proper order of operations?
Which of the following options in limits, conf may provide performance benefits at the forwarding tier?
A single-site indexer cluster has a replication factor of 3, and a search factor of 2. What is true about this cluster?
To activate replication for an index in an indexer cluster, what attribute must be configured in indexes.conf on all peer nodes?
A customer is migrating 500 Universal Forwarders from an old deployment server to a new deployment server, with a different DNS name. The new deployment server is configured and running.
The old deployment server deployed an app containing an updated deploymentclient.conf file to all forwarders, pointing them to the new deployment server. The app was successfully deployed to all 500 forwarders.
Why would all of the forwarders still be phoning home to the old deployment server?
Splunk Enterprise platform instrumentation refers to data that the Splunk Enterprise deployment logs in the _introspection index. Which of the following logs are included in this index? (Select all that apply.)
Which of the following are possible causes of a crash in Splunk? (select all that apply)
(On which Splunk components does the Splunk App for Enterprise Security place the most load?)
Several critical searches that were functioning correctly yesterday are not finding a lookup table today. Which log file would be the best place to start troubleshooting?
To reduce the captain's work load in a search head cluster, what setting will prevent scheduled searches from running on the captain?
(Which of the following data sources are used for the Monitoring Console dashboards?)
What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza?
(Which command is used to initially add a search head to a single-site indexer cluster?)
Which of the following describe migration from single-site to multisite index replication?
(If the maxDataSize attribute is set to auto_high_volume in indexes.conf on a 64-bit operating system, what is the maximum hot bucket size?)
Which of the following security options must be explicitly configured (i.e. which options are not enabled by default)?
Which of the following is a way to exclude search artifacts when creating a diag?
Which of the following is a best practice to maximize indexing performance?
When converting from a single-site to a multi-site cluster, what happens to existing single-site clustered buckets?
Stakeholders have identified high availability for searchable data as their top priority. Which of the following best addresses this requirement?
When using ingest-based licensing, what Splunk role requires the license manager to scale?
Which of the following are client filters available in serverclass.conf? (Select all that apply.)