Splunk SPLK-2002 Practice Exams
Last updated on Oct 08,2026- Exam Code: SPLK-2002
- Exam Name: Splunk Enterprise Certified Architect Exam
- Certification Provider: Splunk
- Latest update: Oct 08,2026
Which of the following is a best practice to maximize indexing performance?
- A . Use automatic source typing.
- B . Use the Splunk default settings.
- C . Not use pre-trained source types.
- D . Minimize configuration generality.
D
Explanation:
A best practice to maximize indexing performance is to minimize configuration generality. Configuration generality refers to the use of generic or default settings for data inputs, such as source type, host, index, and timestamp. Minimizing configuration generality means using specific and accurate settings for each data input, which can reduce the processing overhead and improve the indexing throughput. Using automatic source typing, using the Splunk default settings, and not using pre-trained source types are examples of configuration generality, which can negatively affect the indexing performance
metrics. log is stored in which index?
- A . main
- B . _telemetry
- C . _internal
- D . _introspection
C
Explanation:
According to the Splunk documentation1, metrics.log is a file that contains various metrics data for reviewing product behavior, such as pipeline, queue, thruput, and tcpout_connections. Metrics.log is stored in the _internal index by default2, which is a special index that contains internal logs and metrics for Splunk Enterprise.
The other options are false because:
main is the default index for user data, not internal data3.
_telemetry is an index that contains data collected by the Splunk Telemetry feature, which sends anonymous usage and performance data to Splunk4.
_introspection is an index that contains data collected by the Splunk Monitoring Console, which monitors the health and performance of Splunk components.
What types of files exist in a bucket within a clustered index? (select all that apply)
- A . Inside a replicated bucket, there is only rawdata.
- B . Inside a searchable bucket, there is only tsidx.
- C . Inside a searchable bucket, there is tsidx and rawdata.
- D . Inside a replicated bucket, there is both tsidx and rawdata.
CD
Explanation:
According to the Splunk documentation1, a bucket within a clustered index contains two key types of files: the raw data in compressed form (rawdata) and the indexes that point to the raw data (tsidx files). A bucket can be either replicated or searchable, depending on whether it has both types of files or only the rawdata file. A replicated bucket is a bucket that has been copied from one peer node to another for the purpose of data replication. A searchable bucket is a bucket that has both the rawdata and the tsidx files, and can be searched by the search heads. The types of files that exist in a bucket within a clustered index are:
Inside a searchable bucket, there is tsidx and rawdata. This is true because a searchable bucket contains both the data and the index files, and can be searched by the search heads1.
Inside a replicated bucket, there is both tsidx and rawdata. This is true because a replicated bucket can also be a searchable bucket, if it has both the data and the index files. However, not all replicated buckets are searchable, as some of them might only have the rawdata file, depending on the replication factor and the search factor settings1.
The other options are false because:
Inside a replicated bucket, there is only rawdata. This is false because a replicated bucket can also have the tsidx file, if it is a searchable bucket. A replicated bucket only has the rawdata file if it is a non-searchable bucket, which means that it cannot be searched by the search heads until it gets the tsidx file from another peer node1.
Inside a searchable bucket, there is only tsidx. This is false because a searchable bucket always has both the tsidx and the rawdata files, as they are both required for searching the data. A searchable bucket cannot exist without the rawdata file, as it contains the actual data that the tsidx file points to1.
What types of files exist in a bucket within a clustered index? (select all that apply)
- A . Inside a replicated bucket, there is only rawdata.
- B . Inside a searchable bucket, there is only tsidx.
- C . Inside a searchable bucket, there is tsidx and rawdata.
- D . Inside a replicated bucket, there is both tsidx and rawdata.
CD
Explanation:
According to the Splunk documentation1, a bucket within a clustered index contains two key types of files: the raw data in compressed form (rawdata) and the indexes that point to the raw data (tsidx files). A bucket can be either replicated or searchable, depending on whether it has both types of files or only the rawdata file. A replicated bucket is a bucket that has been copied from one peer node to another for the purpose of data replication. A searchable bucket is a bucket that has both the rawdata and the tsidx files, and can be searched by the search heads. The types of files that exist in a bucket within a clustered index are:
Inside a searchable bucket, there is tsidx and rawdata. This is true because a searchable bucket contains both the data and the index files, and can be searched by the search heads1.
Inside a replicated bucket, there is both tsidx and rawdata. This is true because a replicated bucket can also be a searchable bucket, if it has both the data and the index files. However, not all replicated buckets are searchable, as some of them might only have the rawdata file, depending on the replication factor and the search factor settings1.
The other options are false because:
Inside a replicated bucket, there is only rawdata. This is false because a replicated bucket can also have the tsidx file, if it is a searchable bucket. A replicated bucket only has the rawdata file if it is a non-searchable bucket, which means that it cannot be searched by the search heads until it gets the tsidx file from another peer node1.
Inside a searchable bucket, there is only tsidx. This is false because a searchable bucket always has both the tsidx and the rawdata files, as they are both required for searching the data. A searchable bucket cannot exist without the rawdata file, as it contains the actual data that the tsidx file points to1.
Which of the following items are important sizing parameters when architecting a Splunk environment? (select all that apply)
- A . Number of concurrent users.
- B . Volume of incoming data.
- C . Existence of premium apps.
- D . Number of indexes.
ABC
Explanation:
Number of concurrent users: This is an important factor because it affects the search performance and resource utilization of the Splunk environment. More users mean more concurrent searches, which require more CPU, memory, and disk I/O. The number of concurrent users also determines the search head capacity and the search head clustering configuration12
Volume of incoming data: This is another crucial factor because it affects the indexing performance and storage requirements of the Splunk environment. More data means more indexing throughput, which requires more CPU, memory, and disk I/O. The volume of incoming data also determines the indexer capacity and the indexer clustering configuration13
Existence of premium apps: This is a relevant factor because some premium apps, such as Splunk Enterprise Security and Splunk IT Service Intelligence, have additional requirements and recommendations for the Splunk environment. For example, Splunk Enterprise Security requires a dedicated search head cluster and a minimum of 12 CPU cores per search head. Splunk IT Service Intelligence requires a minimum of 16 CPU cores and 64 GB of RAM per search head45
Reference: 1: Splunk Validated Architectures 2: Search head capacity planning 3: Indexer capacity
planning 4: Splunk Enterprise Security Hardware and Software Requirements 5: [Splunk IT Service Intelligence Hardware and Software Requirements]
What does the deployer do in a Search Head Cluster (SHC)? (Select all that apply.)
- A . Distributes apps to SHC members.
- B . Bootstraps a clean Splunk install for a SHC.
- C . Distributes non-search-related and manual configuration file changes.
- D . Distributes runtime knowledge object changes made by users across the SHC.
A, C
Explanation:
The deployer distributes apps and non-search related and manual configuration file changes to the search head cluster members. The deployer does not bootstrap a clean Splunk install for a search head cluster, as this is done by the captain. The deployer also does not distribute runtime knowledge object changes made by users across the search head cluster, as this is done by the replication factor. For more information, see Use the deployer to distribute apps and configuration updates in the Splunk documentation.
Which command is used for thawing the archive bucket?
- A . Splunk collect
- B . Splunk convert
- C . Splunk rebuild
- D . Splunk dbinspect
C
Explanation:
The splunk rebuild command is used for thawing the archive bucket. Thawing is the process of restoring frozen data back to Splunk for searching. Frozen data is data that has been archived or deleted from Splunk after reaching the end of its retention period. To thaw a bucket, the user needs to copy the bucket from the archive location to the thaweddb directory under SPLUNK_HOME/var/lib/splunk and run the splunk rebuild command to rebuild the .tsidx files for the bucket. The splunk collect command is used for collecting diagnostic data from a Splunk instance. The splunk convert command is used for converting configuration files from one format to another. The splunk dbinspect command is used for inspecting the status and properties of the buckets in an index.
By default, what happens to configurations in the local folder of each Splunk app when it is deployed to a search head cluster?
- A . The local folder is copied to the local folder on the search heads.
- B . The local folder is merged into the default folder and deployed to the search heads.
- C . Only certain . conf files in the local folder are deployed to the search heads.
- D . The local folder is ignored and only the default folder is copied to the search heads.
B
Explanation:
A search head cluster is a group of Splunk Enterprise search heads that share configurations, job scheduling, and search artifacts1. The deployer is a Splunk Enterprise instance that distributes apps and other configurations to the cluster members1. The local folder of each Splunk app contains the custom configurations that override the default settings2. The default folder of each Splunk app contains the default configurations that are provided by the app2.
By default, when the deployer pushes an app to the search head cluster, it merges the local folder of the app into the default folder and deploys the merged folder to the search heads3. This means that the custom configurations in the local folder will take precedence over the default settings in the default folder. However, this also means that the local folder of the app on the search heads will be empty, unless the app is modified through the search head UI3.
Option B is the correct answer because it reflects the default behavior of the deployer when pushing
apps to the search head cluster.
Option A is incorrect because the local folder is not copied to the local folder on the search heads, but merged into the default folder.
Option C is incorrect because all the .conf files in the local folder are deployed to the search heads, not only certain ones.
Option D is incorrect because the local folder is not ignored, but merged into the default folder.
Reference: 1: Search head clustering architecture – Splunk Documentation 2: About configuration files C Splunk Documentation 3: Use the deployer to distribute apps and configuration updates – Splunk Documentation
A Splunk instance has crashed, but no crash log was generated.
There is an attempt to determine what user activity caused the crash by running the following search:

What does searching for closed_txn=0 do in this search?
- A . Filters results to situations where Splunk was started and stopped multiple times.
- B . Filters results to situations where Splunk was started and stopped once.
- C . Filters results to situations where Splunk was stopped and then immediately restarted.
- D . Filters results to situations where Splunk was started, but not stopped.
D
Explanation:
Searching for closed_txn=0 in this search filters results to situations where Splunk was started, but not stopped. This means that the transaction was not completed, and Splunk crashed before it could finish the pipelines. The closed_txn field is added by the transaction command, and it indicates whether the transaction was closed by an event that matches the endswith condition1. A value of 0 means that the transaction was not closed, and a value of 1 means that the transaction was closed1. Therefore, option D is the correct answer, and options A, B, and C are incorrect.
1: transaction command overview