Splunk SPLK-2002 - Splunk Enterprise Certified Architect
What information is written to the __introspection log file?
If .delta replication fails during knowledge bundle replication, what is the fall-back method for Splunk?
A customer plans to ingest 600 GB of data per day into Splunk. They will have six concurrent users, and they also want high data availability and high search performance. The customer is concerned about cost and wants to spend the minimum amount on the hardware for Splunk. How many indexers are recommended for this deployment?
Which Splunk server role regulates the functioning of indexer cluster?
When Splunk indexes data in a non-clustered environment, what kind of files does it create by default?
Which part of the deployment plan is vital prior to installing Splunk indexer clusters and search head clusters?
Which search will show all deployment client messages from the client (UF)?
What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza?
An index has large text log entries with many unique terms in the raw data. Other than the raw data, which index components will take the most space?
On search head cluster members, where in $splunk_home does the Splunk Deployer deploy app content by default?