Which command will permanently decommission a peer node operating in an indexer cluster?
Answer : C
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.2/Indexer/Takeapeeroffline
Which CLI command converts a Splunk instance to a license slave?
Answer : C
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.2/Admin/LicenserCLIcommands
Splunk Enterprise platform instrumentation refers to data that the Splunk Enterprise deployment logs in the _introspection index. Which of the following logs are included in this index? (Select all that apply.)
Answer : CD
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.1/Troubleshooting/Abouttheplatforminstrumentationframework
Which of the following can a Splunk diag contain?
Answer : B
Reference:
https://splunkonbigdata.com/2018/10/01/splunk-diag/
Which of the following are true statements about Splunk indexer clustering?
Answer : B
Reference:
https://answers.splunk.com/answers/760348/search-head-version-compatibility.html
A customer plans to ingest 600 GB of data per day into Splunk. They will have six concurrent users, and they also want high data availability and high search performance. The customer is concerned about cost and wants to spend the minimum amount on the hardware for Splunk. How many indexers are recommended for this deployment?
Answer : D
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.2/Capacity/Summaryofperformancerecommendations
To reduce the captain's work load in a search head cluster, what setting will prevent scheduled searches from running on the captain?
Answer : D
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.1/DistSearch/Adhocclustermember
At which default interval does metrics.log generate a periodic report regarding license utilization?
Answer : B
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.2/Troubleshooting/Aboutmetricslog
Which of the following is a good practice for a search head cluster deployer?
Answer : A
A new Splunk customer is using syslog to collect data from their network devices on port 514. What is the best practice for ingesting this data into Splunk?
Answer : D
Reference:
https://docs.splunk.com/Documentation/SplunkCloud/8.0.0/Data/Monitornetworkports
Which Splunk internal index contains license-related events?
Answer : C
Reference:
https://answers.splunk.com/answers/579494/how-to-display-license-consumed-by-an-index-over-2.html
Which of the following statements describe a Search Head Cluster (SHC) captain? (Select all that apply.)
Answer : AD
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.2/DistSearch/SHCarchitecture#role_of_the_captain
Before users can use a KV store, an admin must create a collection. Where is a collection is defined?
Answer : C
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.2/Knowledge/DefineaKVStorelookupinSplunkWeb
Which search will show all deployment client messages from the client (UF)?
Answer : C
To optimize the distribution of primary buckets; when does primary rebalancing automatically occur? (Select all that apply.)
Answer : ABD
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.2/Indexer/Rebalancethecluster
Have any questions or issues ? Please dont hesitate to contact us