Question 21

Report acceleration has been enabled for a specific use case. In which bucket location is the corresponding CSV file located?
  • Question 22

    A new single-site three indexer cluster is being stood up with replication_factor:2, search_factor:2. At which step would the Indexer Cluster be classed as 'Indexing Ready' and be able to ingest new data?
    Step 1: Install and configure Cluster Master (CM)/Master Node with base clustering stanza settings, restarting CM.
    Step 2: Configure a base app in etc/master-apps on the CM to enable a splunktcp input on port 9997 and deploy index creation configurations.
    Step 3: Install and configure Indexer 1 so that once restarted, it contacts the CM, download the latest config bundle.
    Step 4: Indexer 1 restarts and has successfully joined the cluster.
    Step 5: Install and configure Indexer 2 so that once restarted, it contacts the CM, downloads the latest config bundle Step 6: Indexer 2 restarts and has successfully joined the cluster.
    Step 7: Install and configure Indexer 3 so that once restarted, it contacts the CM, downloads the latest config bundle.
    Step 8: Indexer 3 restarts and has successfully joined the cluster.
  • Question 23

    A non-ES customer has a concern about data availability during a disaster recovery event. Which of the following Splunk Validated Architectures (SVAs) would be recommended for that use case?
  • Question 24

    Which of the following server.conf stanzas indicates the Indexer Discovery feature has not been fully configured (restart pending) on the Master Node?
  • Question 25

    When utilizing a subsearch within a Splunk SPL search query, which of the following statements is accurate?