Test Online Free Splunk SPLK-3002 Exam Questions and Answers
Practice a live sample before buying full access. This page keeps the free SPLK-3002 question set organized by page so visitors and search engines can reach the canonical -questions.html URL directly.
After a notable event has been closed, how long will the meta data for that event remain in the KV Store by default?
Answer: Explanation:
By default, notable event metadata is archived after six months to keep the KV store from growing too large.
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/EA/TrimNECollections
Question 2Selectable Answer
In maintenance mode, which features of KPIs still function?
Answer: Explanation:
It's a best practice to schedule maintenance windows with a 15- to 30-minute time buffer before and after you start and stop your maintenance work. This gives the system an opportunity to catch up with the maintenance state and reduces the chances of ITSI generating false positives during maintenance operations.
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/AboutMW
Question 3Selectable Answer
Which of the following describes entities? (Choose all that apply.)
Anomaly detection can be enabled on which one of the following?
Answer: Explanation:
Enable anomaly detection to identify trends and outliers in KPI search results that might indicate an issue with your system.
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/AD
Question 8Selectable Answer
Which of the following items apply to anomaly detection? (Choose all that apply.)
Which of the following describes a way to delete multiple duplicate entities in ITSI?
Answer: Explanation:
Import entities from CSV files that contain one or more entity definitions. Importing entities from CSV files is an efficient way to define multiple entities.
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/Entity/ImportCSV
Question 10Selectable Answer
Which of the following is a valid type of Multi-KPI Alert?
Which of the following items describe ITSI Backup and Restore functionality? (Choose all that apply.)
Answer: Explanation:
ITSI provides a kvstore_to_json.py script that lets you backup/restore ITSI configuration data, perform bulk service KPI operations, apply time zone offsets for ITSI objects, and regenerate KPI search schedules.
When you run a backup job, ITSI saves your data to a set of JSON files compressed into a single ZIP file.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/kvstorejson
https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/BackupandRestoreITSIconfi g
Question 12Selectable Answer
Within a correlation search, dynamic field values can be specified with what syntax?