Splunk SPLK-2002 Practice Exams
Last updated on Oct 07,2026- Exam Code: SPLK-2002
- Exam Name: Splunk Enterprise Certified Architect Exam
- Certification Provider: Splunk
- Latest update: Oct 07,2026
Which Splunk log file would be the least helpful in troubleshooting a crash?
- A . splunk_instrumentation.log
- B . splunkd_stderr.log
- C . crash-2022-05-13-ll:42:57.1og
- D . splunkd.log
A
Explanation:
The splunk_instrumentation.log file is the least helpful in troubleshooting a crash, because it
contains information about the Splunk Instrumentation feature, which collects and sends usage data
to Splunk Inc. for product improvement purposes. This file does not contain any information about
the Splunk processes, errors, or crashes. The other options are more helpful in troubleshooting a
crash, because they contain relevant information about the Splunk daemon, the standard error
output, and the crash report12
1:
https://docs.splunk.com/Documentation/Splunk/9.1.2/Troubleshooting/WhatSplunklogsaboutitself#splunk_instrumentation.log 2:
https://docs.splunk.com/Documentation/Splunk/9.1.2/Troubleshooting/WhatSplunklogsaboutitself#splunkd_stderr.log
Which Splunk log file would be the least helpful in troubleshooting a crash?
- A . splunk_instrumentation.log
- B . splunkd_stderr.log
- C . crash-2022-05-13-ll:42:57.1og
- D . splunkd.log
A
Explanation:
The splunk_instrumentation.log file is the least helpful in troubleshooting a crash, because it
contains information about the Splunk Instrumentation feature, which collects and sends usage data
to Splunk Inc. for product improvement purposes. This file does not contain any information about
the Splunk processes, errors, or crashes. The other options are more helpful in troubleshooting a
crash, because they contain relevant information about the Splunk daemon, the standard error
output, and the crash report12
1:
https://docs.splunk.com/Documentation/Splunk/9.1.2/Troubleshooting/WhatSplunklogsaboutitself#splunk_instrumentation.log 2:
https://docs.splunk.com/Documentation/Splunk/9.1.2/Troubleshooting/WhatSplunklogsaboutitself#splunkd_stderr.log
As of Splunk 9.0, which index records changes to . conf files?
- A . _configtracker
- B . _introspection
- C . _internal
- D . _audit
A
Explanation:
This is the index that records changes to .conf files as of Splunk 9.0. According to the Splunk documentation1, the _configtracker index tracks the changes made to the configuration files on the Splunk platform, such as the files in the etc directory. The _configtracker index can help monitor and troubleshoot the configuration changes, and identify the source and time of the changes1. The other options are not indexes that record changes to .conf files.
Option B, _introspection, is an index that records the performance metrics of the Splunk platform, such as CPU, memory, disk, and network usage2.
Option C, _internal, is an index that records the internal logs and events of the Splunk platform, such as splunkd, metrics, and audit logs3.
Option D, _audit, is an index that records the audit events of the Splunk platform, such as user authentication, authorization, and activity4. Therefore, option A is the correct answer, and options B, C, and D are incorrect.
1: About the _configtracker index 2: About the _introspection index 3: About the _internal index 4: About the _audit index
Which index-time props.conf attributes impact indexing performance? (Select all that apply.)
- A . REPORT
- B . LINE_BREAKER
- C . ANNOTATE_PUNCT
- D . SHOULD_LINEMERGE
B, D
Explanation:
The index-time props.conf attributes that impact indexing performance are LINE_BREAKER and SHOULD_LINEMERGE. These attributes determine how Splunk breaks the incoming data into events and whether it merges multiple events into one. These operations can affect the indexing speed and the disk space consumption. The REPORT attribute does not impact indexing performance, as it is used to apply transforms at search time. The ANNOTATE_PUNCT attribute does not impact indexing performance, as it is used to add punctuation metadata to events at search time. For more information, see [About props.conf and transforms.conf] in the Splunk documentation.
The master node distributes configuration bundles to peer nodes.
Which directory peer nodes receive the bundles?
- A . apps
- B . deployment-apps
- C . slave-apps
- D . master-apps
C
Explanation:
The master node distributes configuration bundles to peer nodes in the slave-apps directory under $SPLUNK_HOME/etc. The configuration bundle method is the only supported method for managing common configurations and app deployment across the set of peers. It ensures that all peers use the same versions of these files1. Bundles typically contain a subset of files (configuration files and assets) from $SPLUNK_HOME/etc/system, $SPLUNK_HOME/etc/apps, and $SPLUNK_HOME/etc/users2. The process of distributing knowledge bundles means that peers by default receive nearly the entire contents of the search head’s apps3.
Which of the following statements describe a Search Head Cluster (SHC) captain? (Select all that apply.)
- A . Is the job scheduler for the entire SHC.
- B . Manages alert action suppressions (throttling).
- C . Synchronizes the member list with the KV store primary.
- D . Replicates the SHC’s knowledge bundle to the search peers.
A, D
Explanation:
The following statements describe a search head cluster captain:
Is the job scheduler for the entire search head cluster. The captain is responsible for scheduling and dispatching the searches that run on the search head cluster, as well as coordinating the search results from the search peers. The captain also ensures that the scheduled searches are balanced across the search head cluster members and that the search concurrency limits are enforced. Replicates the search head cluster’s knowledge bundle to the search peers. The captain is responsible for creating and distributing the knowledge bundle to the search peers, which contains the knowledge objects that are required for the searches. The captain also ensures that the knowledge bundle is consistent and up-to-date across the search head cluster and the search peers. The following statements do not describe a search head cluster captain:
Manages alert action suppressions (throttling). Alert action suppressions are the settings that prevent an alert from triggering too frequently or too many times. These settings are managed by the search head that runs the alert, not by the captain. The captain does not have any special role in managing alert action suppressions.
Synchronizes the member list with the KV store primary. The member list is the list of search head cluster members that are active and available. The KV store primary is the search head cluster member that is responsible for replicating the KV store data to the other members. These roles are not related to the captain, and the captain does not synchronize them. The member list and the KV store primary are determined by the RAFT consensus algorithm, which is independent of the captain election. For more information, see [About the captain and the captain election] and [About KV store and search head clusters] in the Splunk documentation.
Initialize cluster rebalance operation.
Explanation:
When adding or decommissioning a member from a Search Head Cluster (SHC), the proper order of operations is:
Delete Splunk Enterprise, if it exists.
Install and initialize the instance.
Join the SHC.
This order of operations ensures that the member has a clean and consistent Splunk installation before joining the SHC. Deleting Splunk Enterprise removes any existing configurations and data from the instance. Installing and initializing the instance sets up the Splunk software and the required roles and settings for the SHC. Joining the SHC adds the instance to the cluster and synchronizes the configurations and apps with the other members. The other order of operations are not correct, because they either skip a step or perform the steps in the wrong order.
Configurations from the deployer are merged into which location on the search head cluster member?
- A . SPLUNK_HOME/etc/system/local
- B . SPLUNK_HOME/etc/apps/APP_HOME/local
- C . SPLUNK_HOME/etc/apps/search/default
- D . SPLUNK_HOME/etc/apps/APP_HOME/default
B
Explanation:
Configurations from the deployer are merged into the SPLUNK_HOME/etc/apps/APP_HOME/local directory on the search head cluster member. The deployer distributes apps and other configurations to the search head cluster members in the form of a configuration bundle. The configuration bundle contains the contents of the SPLUNK_HOME/etc/shcluster/apps directory on the deployer. When a search head cluster member receives the configuration bundle, it merges the contents of the bundle into its own SPLUNK_HOME/etc/apps directory. The configurations in the local directory take precedence over the configurations in the default directory. The SPLUNK_HOME/etc/system/local directory is used for system-level configurations, not app-level configurations. The SPLUNK_HOME/etc/apps/search/default directory is used for the default configurations of the search app, not the configurations from the deployer.
Which search head cluster component is responsible for pushing knowledge bundles to search peers, replicating configuration changes to search head cluster members, and scheduling jobs across the search head cluster?
- A . Master
- B . Captain
- C . Deployer
- D . Deployment server
B
Explanation:
The captain is the search head cluster component that is responsible for pushing knowledge bundles to search peers, replicating configuration changes to search head cluster members, and scheduling jobs across the search head cluster. The captain is elected from among the search head cluster members and performs these tasks in addition to serving search requests. The master is the indexer cluster component that is responsible for managing the replication and availability of data across the peer nodes. The deployer is the standalone instance that is responsible for distributing apps and other configurations to the search head cluster members. The deployment server is the instance that is responsible for distributing apps and other configurations to the deployment clients, such as forwarders
The guidance Splunk gives for estimating size on for syslog data is 50% of original data size.
How does this divide between files in the index?
- A . rawdata is: 10%, tsidx is: 40%
- B . rawdata is: 15%, tsidx is: 35%
- C . rawdata is: 35%, tsidx is: 15%
- D . rawdata is: 40%, tsidx is: 10%
B
Explanation:
The guidance Splunk gives for estimating size on for syslog data is 50% of original data size. This divides between files in the index as follows: rawdata is 15%, tsidx is 35%. The rawdata is the compressed version of the original data, which typically takes about 15% of the original data size. The tsidx is the index file that contains the time-series metadata and the inverted index, which typically takes about 35% of the original data size. The total size of the rawdata and the tsidx is about 50% of the original data size. For more information, see [Estimate your storage requirements] in the Splunk documentation.