Splunk SPLK-2002 Practice Exams
Last updated on Oct 07,2026- Exam Code: SPLK-2002
- Exam Name: Splunk Enterprise Certified Architect Exam
- Certification Provider: Splunk
- Latest update: Oct 07,2026
Determining data capacity for an index is a non-trivial exercise.
Which of the following are possible considerations that would affect daily indexing volume? (select all that apply)
- A . Average size of event data.
- B . Number of data sources.
- C . Peak data rates.
- D . Number of concurrent searches on data.
ABC
Explanation:
According to the Splunk documentation1, determining data capacity for an index is a complex task that depends on several factors, such as:
Average size of event data. This is the average number of bytes per event that you send to Splunk. The larger the events, the more storage space they require and the more indexing time they consume.
Number of data sources. This is the number of different types of data that you send to Splunk, such as logs, metrics, network packets, etc. The more data sources you have, the more diverse and complex your data is, and the more processing and parsing Splunk needs to do to index it.
Peak data rates. This is the maximum amount of data that you send to Splunk per second, minute, hour, or day. The higher the peak data rates, the more load and pressure Splunk faces to index the data in a timely manner.
The other option is false because:
Number of concurrent searches on data. This is not a factor that affects daily indexing volume, as it is related to the search performance and the search scheduler, not the indexing process. However, it can affect the overall resource utilization and the responsiveness of Splunk2.
Which two sections can be expanded using the Search Job Inspector?
- A . Execution costs.
- B . Saved search history.
- C . Search job properties.
- D . Optimization suggestions.
C, D
Explanation:
The Search Job Inspector can be used to expand the following sections: Search job properties and Optimization suggestions. The Search Job Inspector is a tool that provides detailed information about a search job, such as the search parameters, the search statistics, the search timeline, and the search log. The Search Job Inspector can be accessed by clicking the Job menu in the Search bar and selecting Inspect Job. The Search Job Inspector has several sections that can be expanded or collapsed by clicking the arrow icon next to the section name. The Search job properties section shows the basic information about the search job, such as the SID, the status, the duration, the disk usage, and the scan count. The Optimization suggestions section shows the suggestions for improving the search performance, such as using transforming commands, filtering events, or reducing fields. The Execution costs and Saved search history sections are not part of the Search Job Inspector, and they cannot be expanded. The Execution costs section is part of the Search Dashboard, which shows the relative costs of each search component, such as commands, lookups, or subsearches. The Saved search history section is part of the Saved Searches page, which shows the history of the saved searches that have been run by the user or by a schedule
Users are asking the Splunk administrator to thaw recently-frozen buckets very frequently.
What could the Splunk administrator do to reduce the need to thaw buckets?
- A . Change f rozenTimePeriodlnSecs to a larger value.
- B . Change maxTotalDataSizeMB to a smaller value.
- C . Change maxHotSpanSecs to a larger value.
- D . Change coldToFrozenDir to a different location.
A
Explanation:
The correct answer is
Of the following types of files within an index bucket, which file type may consume the most disk?
- A . Rawdata
- B . Bloom filter
- C . Metadata (.data)
- D . Inverted index (.tsidx)
A
Explanation:
Of the following types of files within an index bucket, the rawdata file type may consume the most disk. The rawdata file type contains the compressed and encrypted raw data that Splunk has ingested. The rawdata file type is usually the largest file type in a bucket, because it stores the original data without any filtering or extraction. The bloom filter file type contains a probabilistic data structure that is used to determine if a bucket contains events that match a given search. The bloom filter file type is usually very small, because it only stores a bit array of hashes. The metadata (.data) file type contains information about the bucket properties, such as the earliest and latest event timestamps, the number of events, and the size of the bucket. The metadata file type is also usually very small, because it only stores a few lines of text. The inverted index (.tsidx) file type contains the time-series index that maps the timestamps and event IDs of the raw data. The inverted index file type can vary in size depending on the number and frequency of events, but it is usually smaller than the rawdata file type
A monitored log file is changing on the forwarder. However, Splunk searches are not finding any new data that has been added.
What are possible causes? (select all that apply)
- A . An admin ran splunk clean eventdata -index <indexname> on the indexer.
- B . An admin has removed the Splunk fishbucket on the forwarder.
- C . The last 256 bytes of the monitored file are not changing.
- D . The first 256 bytes of the monitored file are not changing.
BC
Explanation:
A monitored log file is changing on the forwarder, but Splunk searches are not finding any new data that has been added.
This could be caused by two possible reasons:
B. An admin has removed the Splunk fishbucket on the forwarder.
C. The last 256 bytes of the monitored file are not changing.
Option B is correct because the Splunk fishbucket is a directory that stores information about the files that have been monitored by Splunk, such as the file name, size, modification time, and CRC checksum. If an admin removes the fishbucket, Splunk will lose track of the files that have been previously indexed and will not index any new data from those files.
Option C is correct because Splunk uses the CRC checksum of the last 256 bytes of a monitored file to determine if the file has changed since the last time it was read. If the last 256 bytes of the file are not changing, Splunk will assume that the file is unchanged and will not index any new data from it.
Option A is incorrect because running the splunk clean eventdata -index <indexname> command on the indexer will delete all the data from the specified index, but it will not affect the forwarder’s ability to send new data to the indexer.
Option D is incorrect because Splunk does not use the first 256 bytes of a monitored file to determine if the file has changed12
1: https://docs.splunk.com/Documentation/Splunk/9.1.2/Data/Monitorfilesanddirectories 2: https://docs.splunk.com/Documentation/Splunk/9.1.2/Troubleshooting/Didyouloseyourfishbucket
In search head clustering, which of the following methods can you use to transfer captaincy to a different member? (Select all that apply.)
- A . Use the Monitoring Console.
- B . Use the Search Head Clustering settings menu from Splunk Web on any member.
- C . Run the splunk transfer shcluster-captain command from the current captain.
- D . Run the splunk transfer shcluster-captain command from the member you would like to become the captain.
B, D
Explanation:
In search head clustering, there are two methods to transfer captaincy to a different member. One method is to use the Search Head Clustering settings menu from Splunk Web on any member. This method allows the user to select a specific member to become the new captain, or to let Splunk choose the best candidate. The other method is to run the splunk transfer shcluster-captain command from the member that the user wants to become the new captain. This method requires the user to know the name of the target member and to have access to the CLI of that member. Using the Monitoring Console is not a method to transfer captaincy, because the Monitoring Console does not have the option to change the captain. Running the splunk transfer shcluster-captain command from the current captain is not a method to transfer captaincy, because this command will fail with an error message
Which command will permanently decommission a peer node operating in an indexer cluster?
- A . splunk stop -f
- B . splunk offline -f
- C . splunk offline –enforce-counts
- D . splunk decommission –enforce counts
C
Explanation:
The splunk offline –enforce-counts command will permanently decommission a peer node operating in an indexer cluster. This command will remove the peer node from the cluster and delete its data. This command should be used when the peer node is no longer needed or is being replaced by another node. The splunk stop -f command will stop the Splunk service on the peer node, but it will not decommission it from the cluster. The splunk offline -f command will take the peer node offline, but it will not delete its data or enforce the replication and search factors. The splunk decommission – -enforce-counts command is not a valid Splunk command. For more information, see Remove a peer node from an indexer cluster in the Splunk documentation.
What is the minimum reference server specification for a Splunk indexer?
- A . 12 CPU cores, 12GB RAM, 800 IOPS
- B . 16 CPU cores, 16GB RAM, 800 IOPS
- C . 24 CPU cores, 16GB RAM, 1200 IOPS
- D . 28 CPU cores, 32GB RAM, 1200 IOPS
A
Explanation:
The minimum reference server specification for a Splunk indexer is 12 CPU cores, 12GB RAM, and 800 IOPS. This specification is based on the assumption that the indexer will handle an average indexing volume of 100GB per day, with a peak of 300GB per day, and a typical search load of 1 concurrent search per 1GB of indexing volume. The other specifications are either higher or lower than the minimum requirement. For more information, see [Reference hardware] in the Splunk documentation.
In an existing Splunk environment, the new index buckets that are created each day are about half the size of the incoming data. Within each bucket, about 30% of the space is used for raw data and about 70% for index files.
What additional information is needed to calculate the daily disk consumption, per indexer, if indexer clustering is implemented?
- A . Total daily indexing volume, number of peer nodes, and number of accelerated searches.
- B . Total daily indexing volume, number of peer nodes, replication factor, and search factor.
- C . Total daily indexing volume, replication factor, search factor, and number of search heads.
- D . Replication factor, search factor, number of accelerated searches, and total disk size across cluster.
B
Explanation:
The additional information that is needed to calculate the daily disk consumption, per indexer, if indexer clustering is implemented, is the total daily indexing volume, the number of peer nodes, the replication factor, and the search factor. These information are required to estimate how much data is ingested, how many copies of raw data and searchable data are maintained, and how many indexers are involved in the cluster. The number of accelerated searches, the number of search heads, and the total disk size across the cluster are not relevant for calculating the daily disk consumption, per indexer. For more information, see [Estimate your storage requirements] in the Splunk documentation.
In a four site indexer cluster, which configuration stores two searchable copies at the origin site, one searchable copy at site2, and a total of four searchable copies?
- A . site_search_factor = origin:2, site1:2, total:4
- B . site_search_factor = origin:2, site2:1, total:4
- C . site_replication_factor = origin:2, site1:2, total:4
- D . site_replication_factor = origin:2, site2:1, total:4
B
Explanation:
In a four site indexer cluster, the configuration that stores two searchable copies at the origin site, one searchable copy at site2, and a total of four searchable copies is site_search_factor = origin:2, site2:1, total:4. This configuration tells the cluster to maintain two copies of searchable data at the site where the data originates, one copy of searchable data at site2, and a total of four copies of searchable data across all sites. The site_search_factor determines how many copies of searchable data are maintained by the cluster for each site. The site_replication_factor determines how many copies of raw data are maintained by the cluster for each site. For more information, see Configure multisite indexer clusters with server.conf in the Splunk documentation.