10 free sample questions from a bank of 161, with the correct answers and explanations. No signup required — start practising right now.
1Which of the following will cause the greatest reduction in disk size requirements for a cluster of N indexers running Splunk Enterprise Security?
Setting the cluster search factor to N-1.
Increasing the number of buckets per index.
Decreasing the data model acceleration range.
Setting the cluster replication factor to N-1.
Answer: A
2Which index-time props.conf attributes impact indexing performance? (Select all that apply.)
REPORT
LINE_BREAKER
ANNOTATE_PUNCT
SHOULD_LINEMERGE
Answer: B, C
3Which of the following are client filters available in serverclass.conf? (Select all that apply.)
DNS name.
IP address.
Splunk server role.
Platform (machine type).
Answer: A, B
4What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza?
btool.log
metrics.log
splunkd.log
tailing_processor.log
Answer: C
5Which Splunk tool offers a health check for administrators to evaluate the health of their Splunk deployment?
btool
DiagGen
SPL Clinic
Monitoring Console
Answer: D
6In a four site indexer cluster, which configuration stores two searchable copies at the origin site, one searchable copy at site2, and a total of four searchable copies?
7Which Splunk Enterprise offering has its own license?
Splunk Cloud Forwarder
Splunk Heavy Forwarder
Splunk Universal Forwarder
Splunk Forwarder Management
Answer: C
8Which component in the splunkd.log will log information related to bad event breaking?
Audittrail
EventBreaking
IndexingPipeline
AggregatorMiningProcessor
Answer: D
9Which Splunk server role regulates the functioning of indexer cluster?
Indexer
Deployer
Master Node
Monitoring Console
Answer: C
10When adding or rejoining a member to a search head cluster, the following error is displayed:
Error pulling configurations from the search head cluster captain; consider performing a destructive configuration resync on this search head cluster member.
What corrective action should be taken?
Restart the search head.
Run the splunk apply shcluster-bundle command from the deployer.
Run the clean raft command on all members of the search head cluster.
Run the splunk resync shcluster-replicated-config command on this member.