Splunk SPLK-2002 - Splunk Enterprise Certified Architect
(A customer has an environment with a Search Head Cluster and an indexer cluster. They are troubleshooting license usage data, including indexed volume in bytes per pool, index, host, sourcetype, and source. Where should the license_usage.log file be retrieved from in this environment?)
Which of the following items are important sizing parameters when architecting a Splunk environment? (select all that apply)
Configurations from the deployer are merged into which location on the search head cluster member?
Which of the following are possible causes of a crash in Splunk? (select all that apply)
Which server.conf attribute should be added to the master node's server.conf file when decommissioning a site in an indexer cluster?
Users who receive a link to a search are receiving an "Unknown sid" error message when they open the link.
Why is this happening?
A multi-site indexer cluster can be configured using which of the following? (Select all that apply.)
(On which Splunk components does the Splunk App for Enterprise Security place the most load?)
When adding or rejoining a member to a search head cluster, the following error is displayed:
Error pulling configurations from the search head cluster captain; consider performing a destructive configuration resync on this search head cluster member.
What corrective action should be taken?
(Where can files be placed in a configuration bundle on a search peer that will persist after a new configuration bundle has been deployed?)
