Free Demo Questions

Test Online Free Splunk SPLK-3002 Exam Questions and Answers

Practice a live sample before buying full access. This page keeps the free SPLK-3002 question set organized by page so visitors and search engines can reach the canonical -questions.html URL directly.

Updated May 20, 2024 12 Questions 1 Pages
Page 1 of 1
Question 1 Selectable Answer
After a notable event has been closed, how long will the meta data for that event remain in the KV Store by default?

Answer:
Explanation:
By default, notable event metadata is archived after six months to keep the KV store from growing too large.
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/EA/TrimNECollections
Question 2 Selectable Answer
In maintenance mode, which features of KPIs still function?

Answer:
Explanation:
It's a best practice to schedule maintenance windows with a 15- to 30-minute time buffer before and after you start and stop your maintenance work. This gives the system an opportunity to catch up with the maintenance state and reduces the chances of ITSI generating false positives during maintenance operations.
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/AboutMW
Question 3 Selectable Answer
Which of the following describes entities? (Choose all that apply.)

Answer:
Explanation:
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/KPIfilter
Question 4 Selectable Answer
Which of the following is a characteristic of base searches?

Answer:
Explanation:
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/BaseSearch
Question 5 Selectable Answer
What is the main purpose of the service analyzer?

Answer:
Question 6 Selectable Answer
Which of the following is a recommended best practice for service and glass table design?

Answer:
Explanation:
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/GTOverview
Question 7 Selectable Answer
Anomaly detection can be enabled on which one of the following?

Answer:
Explanation:
Enable anomaly detection to identify trends and outliers in KPI search results that might indicate an issue with your system.
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/AD
Question 8 Selectable Answer
Which of the following items apply to anomaly detection? (Choose all that apply.)

Answer:
Explanation:
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/AD
Question 9 Selectable Answer
Which of the following describes a way to delete multiple duplicate entities in ITSI?

Answer:
Explanation:
Import entities from CSV files that contain one or more entity definitions. Importing entities from CSV files is an efficient way to define multiple entities.
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/Entity/ImportCSV
Question 10 Selectable Answer
Which of the following is a valid type of Multi-KPI Alert?

Answer:
Explanation:
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/MKA
Question 11 Selectable Answer
Which of the following items describe ITSI Backup and Restore functionality? (Choose all that apply.)

Answer:
Explanation:
ITSI provides a kvstore_to_json.py script that lets you backup/restore ITSI configuration data, perform bulk service KPI operations, apply time zone offsets for ITSI objects, and regenerate KPI search schedules.
When you run a backup job, ITSI saves your data to a set of JSON files compressed into a single ZIP file.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/kvstorejson
https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/BackupandRestoreITSIconfi g
Question 12 Selectable Answer
Within a correlation search, dynamic field values can be specified with what syntax?

Answer:
Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/8.2.2/Search/Searchindexes
Showing page 1 of 1