Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Splunk SPLK-3002 - Splunk IT Service Intelligence Certified Admin Exam

Page: 2 / 3
Total 96 questions

Which of the following applies when configuring time policies for KPI thresholds?

A.

A person can only configure 24 policies, one for each hour of the day.

B.

They are great if you expect normal behavior at 1:00 to be different than normal behavior at 5:00

C.

If a person expects a KPI to change significantly through a cycle on a daily basis, don’t use it.

D.

It is possible for multiple time policies to overlap.

In which index are active notable events stored?

A.

itsi_notable_archive

B.

itsi_notable_audit

C.

itsi_tracked_alerts

D.

itsi_tracked_groups

How should entities be handled during the data audit phase of requirements gathering?

A.

Entity meta-data for info and aliases should be identified and recorded as requirements.

B.

Entities should be noted based upon Service KPI requirements such as 'by host' or 'by product line'.

C.

Entities must be identified for every Service KPI defined and recorded in requirements.

D.

Entities identified should be included in the entity filtering requirements, such as 'by processld' or 'by host'.

Which of the following describes default deep dives?

A.

Are manually generated and can be accessed via the Service Analyzer.

B.

Include all KPIs of all services.

C.

Are auto-generated and can be accessed via the Service Analyzer.

D.

Include health scores of all services.

Which of the following items apply to anomaly detection? (Choose all that apply.)

A.

Use AD on KPIs that have an unestablished baseline of data points. This allows the ML pattern to perform it’s magic.

B.

A minimum of 24 hours of data is needed for anomaly detection, and a minimum of 4 entities for cohesive analysis.

C.

Anomaly detection automatically generates notable events when KPI data diverges from the pattern.

D.

There are 3 types of anomaly detection supported in ITSI: adhoc, trending, and cohesive.

After ITSI is initially deployed for the operations department at a large company, another department would like to use ITSI but wants to keep their information private from the operations group. How can this be achieved?

A.

Create service templates for each group and create the services from the templates.

B.

Create teams for each department and assign KPIs to each team.

C.

Create services for each group and set the permissions of the services to restrict them to each group.

D.

Create teams for each department and assign services to the teams.

Which of the following best describes a default deep dive?

A.

It initially shows the health scores for all services.

B.

It initially shows the highest importance KPIs.

C.

It initially shows all of the KPIs for a selected service.

D.

It initially shows all the entity swim lanes.

Which of the following is an advantage of using adaptive time thresholds?

A.

Automatically update thresholds daily to manage dynamic changes to KPI values.

B.

Automatically adjust KPI calculation to manage dynamic event data.

C.

Automatically adjust aggregation policy grouping to manage escalating severity.

D.

Automatically adjust correlation search thresholds to adjust sensitivity over time.

Which step is required to install ITSI on a single Search Head?

A.

Untar the ITSI package in /etc/apps

B.

Run splunk_apply shcluster-bundle

C.

Use the Splunk -> Manage Apps Dashboard to download and install.

D.

All of the above.

Which of the following are characteristics of ITSI service dependencies? (select all that apply)

A.

If a primary service has a dependent service KPI and the KPI's importance level is changed, the dependency is broken.

B.

It is best practice to use the dependent service's built-in 'ServiceHealthScore' KPI to reflect impact to the primary service.

C.

Setting the dependent service KPI importance level will be treated as any other KPI in the primary service's health score.

D.

Impactful dependent services should only be configured to one primary service to avoid false negatives in Multi KPI Alerts.