Questions for the SPLK-3002 were updated on : Nov 16 ,2024
After a notable event has been closed, how long will the meta data for that event remain in the KV
Store by default?
A
Explanation:
By default, notable event metadata is archived after six months to keep the KV store from growing
too large.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/EA/TrimNECollections
Which of the following is a best practice for identifying the most effective services with which to start
an iterative ITSI deployment?
A
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/MKA
When creating a custom deep dive, what color are services/KPIs in maintenance mode within the
topology view?
A
Explanation:
Services, entities, and KPIs that are fully or partially impacted by a maintenance window appear in a
dark gray color on pages that display health scores, including service analyzers, service and entity
details pages, glass tables, multi-KPI alerts, and deep dives.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/AboutMW
Which deep dive swim lane type does not require writing SPL?
B
Explanation:
Among all the search configurations, automatic lane doesnt need to be written in Splunk Processing
language.
Which of the following items apply to anomaly detection? (Choose all that apply.)
B, C
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/AD
Which of the following is a best practice when configuring maintenance windows?
C
Explanation:
It's a best practice to schedule maintenance windows with a 15- to 30-minute time buffer before and
after you start and stop your maintenance work.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/AboutMW
In Episode Review, what is the result of clicking an episode’s Acknowledge button?
C
Explanation:
When an episode warrants investigation, the analyst acknowledges the episode, which moves the
status fromNewtoIn Progress.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/EA/EpisodeOverview
Which glass table feature can be used to toggle displaying KPI values from more than one service on
a single widget?
C
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/Visualizations#collapseDesktop8
Which of the following is a characteristic of base searches?
B
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/BaseSearch
What are valid ITSI Glass Table editor capabilities? (Choose all that apply.)
A, C, D
Explanation:
Create a glass table to visualize and monitor the interrelationships and dependencies across your IT
and business services.
The service swapping settings are saved and apply the next time you open the glass table.
You can add metrics like KPIs, ad hoc searches, and service health scores that update in real time
against a background that you design. Glass tables show real-time data generated by KPIs and
services.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/GTOverview
Which of the following is the best use case for configuring a Multi-KPI Alert?
A
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/MKA
In distributed search, which components need to be installed on instances other than the search
head?
A
Explanation:
SA-IndexCreationis required on all indexers. For non-clustered, distributed environments, copySA-
IndexCreationto$SPLUNK_HOME/etc/apps/on individual indexers.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/Install/InstallDD
When deploying ITSI on a distributed Splunk installation, which component must be installed on the
search head(s)?
D
Explanation:
InstallSA-ITSI-LicensecheckerandSA-UserAccesson anylicense masterin a distributed or search
head cluster environment. If a search head in your environment is also a license master, the license
master components are installed when you install ITSI on the search heads.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/Install/InstallDD
Which of the following describes entities? (Choose all that apply.)
D
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/KPIfilter
Which of the following describes a realistic troubleshooting workflow in ITSI?
A
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/IModules/Troubleshootingmodules