SPLK-2002 Exam Question 1

When Splunk is installed, where are the internal indexes stored by default?
  • SPLK-2002 Exam Question 2

    In a distributed environment, knowledge object bundles are replicated from the search head to which location
    on the search peer(s)?
  • SPLK-2002 Exam Question 3

    A Splunk instance has the following settings in SPLUNK_HOME/etc/system/local/server.conf:
    [clustering]
    mode = master
    replication_factor = 2
    pass4SymmKey = password123
    Which of the following statements describe this Splunk instance? (Select all that apply.)
  • SPLK-2002 Exam Question 4

    Which of the following is true regarding Splunk Enterprise performance? (Select all that apply.)
  • SPLK-2002 Exam Question 5

    A new Splunk customer is using syslog to collect data from their network devices on port 514. What is the best practice for ingesting this data into Splunk?