Splunk SPLK-2002 - Splunk Enterprise Certified Architect
The guidance Splunk gives for estimating size on for syslog data is 50% of original data size. How does this divide between files in the index?
Which of the following use cases would be made possible by multi-site clustering? (select all that apply)
Which of the following strongly impacts storage sizing requirements for Enterprise Security?
A customer has a four site indexer cluster. The customer has requirements to store five copies of searchable data, with one searchable copy of data at the origin site, and one searchable copy at the disaster recovery site (site4).
Which configuration meets these requirements?
A monitored log file is changing on the forwarder. However, Splunk searches are not finding any new data that has been added. What are possible causes? (select all that apply)
Which part of the deployment plan is vital prior to installing Splunk indexer clusters and search head clusters?
A customer currently has many deployment clients being managed by a single, dedicated deployment server. The customer plans to double the number of clients.
What could be done to minimize performance issues?
metrics. log is stored in which index?
(A customer has converted a CSV lookup to a KV Store lookup. What must be done to make it available for an automatic lookup?)
What is a Splunk Job? (Select all that apply.)
