Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Splunk SPLK-3002 - Splunk IT Service Intelligence Certified Admin Exam

Page: 1 / 3
Total 96 questions

Which of the following actions can be performed with a deep dive?

A.

Create a Multi-KPI alert from the deep dive's current state to warn of similar situations in the future.

B.

Create a predictive analysis model from the deep dive to warn of future service degradation.

C.

Create an anomaly detection alert to show when the same pattern begins in the future.

D.

Create a custom service analyzer from selected deep dive lanes.

In distributed search, which components need to be installed on instances other than the search head?

A.

SA-IndexCreation and SA-ITSI-Licensechecker on indexers.

B.

SA-IndexCreation and SA-ITOA on indexers; SA-ITSI-Licensechecker and SA-UserAccess on the license master.

C.

SA-IndexCreation on idexers; SA-ITSI-Licensechecker and SA-UserAccess on the license master.

D.

SA-ITSI-Licensechecker on indexers.

Within a correlation search, dynamic field values can be specified with what syntax?

A.

fieldname

B.

C.

%fieldname%

D.

eval(fieldname)

To use Adaptive Threshholding, what is the minimum requirement for a set of KPI data?

A.

14 days old.

B.

7 days old.

C.

30 days old.

D.

10 days old.

Which deep dive swim lane type does not require writing SPL?

A.

Event lane.

B.

Automatic lane.

C.

Metric lane.

D.

KPI lane.

Fritz is looking at a Deep Dive with a lane showing the average percent of CPU usage across the four web servers in the web farm. Seeing a spike, he wants to add the graphs of each server on the swim lane, and selects the Lane Overlay Options to do so. No entity overlays are available for the KPI.

What is wrong with his KPI configuration?

A.

He did not split the KPI by entity.

B.

He did not enable entity filtering.

C.

He configured the KPI to split by pseudo‑entity.

D.

He configured the service with only three entities.

Which of the following are deployment recommendations for ITSI? (Choose all that apply.)

A.

Deployments often require an increase of hardware resources above base Splunk requirements.

B.

Deployments require a dedicated ITSI search head.

C.

Deployments may increase the number of required indexers based on the number of KPI searches.

D.

Deployments should use fastest possible disk arrays for indexers.

What are valid ITSI Glass Table editor capabilities? (Choose all that apply.)

A.

Creating glass tables.

B.

Correlation search creation.

C.

Service swapping configuration.

D.

Adding KPI metric lanes to glass tables.

When installing ITSI to support a Distributed Search Architecture, which of the following items apply? (Choose all that apply.)

A.

Copy SA-IndexCreation to all indexers.

B.

Copy SA-IndexCreation to the etc/apps directory on the index cluster master node.

C.

Extract installer package into etc/apps directory of the cluster deployer node.

D.

Extract ITSI app package into etc/apps directory of search head.

Which of the following are characteristics of service templates? (select all that apply)

A.

Service templates can be modified after services are instantiated from it.

B.

Service templates contain KPIs and KPI thresholds.

C.

Service templates can contain specific or generic entity rules.

D.

Service templates contain domain specific dashboards and deep dives.