Question 1

In an existing Splunk environment, the new index buckets that are created each day are about half the size of the incoming data. Within each bucket, about 30% of the space is used for rawdata and about 70% for index files.
What additional information is needed to calculate the daily disk consumption, per indexer, if indexer clustering is implemented?
  • Question 2

    What does setting site=site0on all Search Head Cluster members do in a multi-site indexer cluster?
  • Question 3

    What is the default log size for Splunk internal logs?
  • Question 4

    Which command will permanently decommission a peer node operating in an indexer cluster?
  • Question 5

    Which of the following are true statements about Splunk indexer clustering?