1.
Which of the following should be included in a deployment plan?
2.
A multi-site indexer cluster can be configured using which of the following? (Select all that apply.)
3.
What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza?
4.
Which Splunk tool offers a health check for administrators to evaluate the health of their Splunk deployment?
5.
In a four site indexer cluster, which configuration stores two searchable copies at the origin site, one searchable copy at site2, and a total of four searchable copies?
6.
Which of the following is true regarding Splunk Enterprise performance? (Select all that apply.)
7.
Which Splunk Enterprise offering has its own license?
8.
The guidance Splunk gives for estimating size on for syslog data is 50% of original data size. How does this divide between files in the index?
9.
In an existing Splunk environment, the new index buckets that are created each day are about half the size of the incoming data. Within each bucket, about 30% of the space is used for rawdata and about 70% for index files. What additional information is needed to calculate the daily disk consumption, per indexer, if indexer clustering is implemented?
10.
A three-node search head cluster is skipping a large number of searches across time. What should be done to increase scheduled search capacity on the search head cluster?