Splunk SPLK-2002 Practice Exams
Last updated on Oct 07,2026- Exam Code: SPLK-2002
- Exam Name: Splunk Enterprise Certified Architect Exam
- Certification Provider: Splunk
- Latest update: Oct 07,2026
Which of the following are client filters available in serverclass.conf? (Select all that apply.)
- A . DNS name.
- B . IP address.
- C . Splunk server role.
- D . Platform (machine type).
A, B, D
Explanation:
The client filters available in serverclass.conf are DNS name, IP address, and platform (machine type). These filters allow the administrator to specify which forwarders belong to a server class and receive the apps and configurations from the deployment server. The Splunk server role is not a valid client filter in serverclass.conf, as it is not a property of the forwarder. For more information, see [Use forwarder management filters] in the Splunk documentation.
A multi-site indexer cluster can be configured using which of the following? (Select all that apply.)
- A . Via Splunk Web.
- B . Directly edit SPLUNK_HOME/etc./system/local/server.conf
- C . Run a Splunk edit cluster-config command from the CLI.
- D . Directly edit SPLUNK_HOME/etc/system/default/server.conf
B, C
Explanation:
A multi-site indexer cluster can be configured by directly editing SPLUNK_HOME/etc/system/local/server.conf or running a splunk edit cluster-config command from the CLI. These methods allow the administrator to specify the site attribute for each indexer node and the site_replication_factor and site_search_factor for the cluster. Configuring a multi-site indexer cluster via Splunk Web or directly editing SPLUNK_HOME/etc/system/default/server.conf are not supported methods. For more information, see Configure the indexer cluster with server.conf in the Splunk documentation.
A customer currently has many deployment clients being managed by a single, dedicated deployment server. The customer plans to double the number of clients.
What could be done to minimize performance issues?
- A . Modify deploymentclient. conf to change from a Pull to Push mechanism.
- B . Reduce the number of apps in the Manager Node repository.
- C . Increase the current deployment client phone home interval.
- D . Decrease the current deployment client phone home interval.
C
Explanation:
According to the Splunk documentation1, increasing the current deployment client phone home interval can minimize performance issues by reducing the frequency of communication between the clients and the deployment server. This can also reduce the network traffic and the load on the deployment server. The other options are false because:
Modifying deploymentclient.conf to change from a Pull to Push mechanism is not possible, as Splunk does not support a Push mechanism for deployment server2.
Reducing the number of apps in the Manager Node repository will not affect the performance of the deployment server, as the apps are only downloaded when there is a change in the configuration or a new app is added3.
Decreasing the current deployment client phone home interval will increase the performance issues, as it will increase the frequency of communication between the clients and the deployment server, resulting in more network traffic and load on the deployment server1.
When should a dedicated deployment server be used?
- A . When there are more than 50 search peers.
- B . When there are more than 50 apps to deploy to deployment clients.
- C . When there are more than 50 deployment clients.
- D . When there are more than 50 server classes.
C
Explanation:
A dedicated deployment server is a Splunk instance that manages the distribution of configuration updates and apps to a set of deployment clients, such as forwarders, indexers, or search heads. A dedicated deployment server should be used when there are more than 50 deployment clients, because this number exceeds the recommended limit for a non-dedicated deployment server. A non-dedicated deployment server is a Splunk instance that also performs other roles, such as indexing or searching. Using a dedicated deployment server can improve the performance, scalability, and reliability of the deployment process.
Option C is the correct answer.
Option A is incorrect because the number of search peers does not affect the need for a dedicated deployment server. Search peers are indexers that participate in a distributed search.
Option B is incorrect because the number of apps to deploy does not affect the need for a dedicated deployment server. Apps are packages of configurations and assets that provide specific functionality or views in Splunk.
Option D is incorrect because the number of server classes does not affect the need for a dedicated deployment
server. Server classes are logical groups of deployment clients that share the same configuration updates and apps12
1: https://docs.splunk.com/Documentation/Splunk/9.1.2/Updating/Aboutdeploymentserver 2: https://docs.splunk.com/Documentation/Splunk/9.1.2/Updating/Whentousedeploymentserver
When Splunk indexes data in a non-clustered environment, what kind of files does it create by default?
- A . Index and .tsidx files.
- B . Rawdata and index files.
- C . Compressed and .tsidx files.
- D . Compressed and meta data files.
A
Explanation:
When Splunk indexes data in a non-clustered environment, it creates index and .tsidx files by default. The index files contain the raw data that Splunk has ingested, compressed and encrypted. The .tsidx files contain the time-series index that maps the timestamps and event IDs of the raw data. The rawdata and index files are not the correct terms for the files that Splunk creates. The compressed and .tsidx files are partially correct, but compressed is not the proper name for the index files. The compressed and meta data files are also partially correct, but meta data is not the proper name for the .tsidx files.
When troubleshooting monitor inputs, which command checks the status of the tailed files?
- A . splunk cmd btool inputs list | tail
- B . splunk cmd btool check inputs layer
- C . curl https://serverhost:8089/services/admin/inputstatus/TailingProcessor:FileStatus
- D . curl https://serverhost:8089/services/admin/inputstatus/TailingProcessor:Tailstatus
C
Explanation:
The curl https://serverhost:8089/services/admin/inputstatus/TailingProcessor:FileStatus command is used to check the status of the tailed files when troubleshooting monitor inputs. Monitor inputs are inputs that monitor files or directories for new data and send the data to Splunk for indexing. The TailingProcessor:FileStatus endpoint returns information about the files that are being monitored by the Tailing Processor, such as the file name, path, size, position, and status. The splunk cmd btool inputs list | tail command is used to list the inputs configurations from the inputs.conf file and pipe the output to the tail command. The splunk cmd btool check inputs layer command is used to check the inputs configurations for syntax errors and layering. The curl https://serverhost:8089/services/admin/inputstatus/TailingProcessor:Tailstatus command does not exist, and it is not a valid endpoint.
What is the default log size for Splunk internal logs?
- A . 10MB
- B . 20 MB
- C . 25MB
- D . 30MB
C
Explanation:
Splunk internal logs are stored in the SPLUNK_HOME/var/log/splunk directory by default. The default log size for Splunk internal logs is 25 MB, which means that when a log file reaches 25 MB, Splunk rolls it to a backup file and creates a new log file. The default number of backup files is 5, which means that Splunk keeps up to 5 backup files for each log file
Which of the following describe migration from single-site to multisite index replication?
- A . A master node is required at each site.
- B . Multisite policies apply to new data only.
- C . Single-site buckets instantly receive the multisite policies.
- D . Multisite total values should not exceed any single-site factors.
B
Explanation:
Migration from single-site to multisite index replication only affects new data, not existing data. Multisite policies apply to new data only, meaning that data that is ingested after the migration will follow the multisite replication and search factors. Existing data, or data that was ingested before the migration, will retain the single-site policies, unless they are manually converted to multisite buckets. Single-site buckets do not instantly receive the multisite policies, nor do they automatically convert to multisite buckets. Multisite total values can exceed any single-site factors, as long as they do not exceed the number of peer nodes in the cluster. A master node is not required at each site, only one master node is needed for the entire cluster
A single-site indexer cluster has a replication factor of 3, and a search factor of 2.
What is true about this cluster?
- A . The cluster will ensure there are at least two copies of each bucket, and at least three copies of searchable metadata.
- B . The cluster will ensure there are at most three copies of each bucket, and at most two copies of searchable metadata.
- C . The cluster will ensure only two search heads are allowed to access the bucket at the same time.
- D . The cluster will ensure there are at least three copies of each bucket, and at least two copies of searchable metadata.
D
Explanation:
A single-site indexer cluster is a group of Splunk Enterprise instances that index and replicate data across the cluster1. A bucket is a directory that contains indexed data, along with metadata and other information2. A replication factor is the number of copies of each bucket that the cluster maintains1. A search factor is the number of searchable copies of each bucket that the cluster maintains1. A searchable copy is a copy that contains both the raw data and the index files3. A search head is a Splunk Enterprise instance that coordinates the search activities across the peer nodes1.
Option D is the correct answer because it reflects the definitions of replication factor and search factor. The cluster will ensure that there are at least three copies of each bucket, one on each peer node, to satisfy the replication factor of 3. The cluster will also ensure that there are at least two searchable copies of each bucket, one primary and one searchable, to satisfy the search factor of
A single-site indexer cluster has a replication factor of 3, and a search factor of 2.
What is true about this cluster?
- A . The cluster will ensure there are at least two copies of each bucket, and at least three copies of searchable metadata.
- B . The cluster will ensure there are at most three copies of each bucket, and at most two copies of searchable metadata.
- C . The cluster will ensure only two search heads are allowed to access the bucket at the same time.
- D . The cluster will ensure there are at least three copies of each bucket, and at least two copies of searchable metadata.
D
Explanation:
A single-site indexer cluster is a group of Splunk Enterprise instances that index and replicate data across the cluster1. A bucket is a directory that contains indexed data, along with metadata and other information2. A replication factor is the number of copies of each bucket that the cluster maintains1. A search factor is the number of searchable copies of each bucket that the cluster maintains1. A searchable copy is a copy that contains both the raw data and the index files3. A search head is a Splunk Enterprise instance that coordinates the search activities across the peer nodes1.
Option D is the correct answer because it reflects the definitions of replication factor and search factor. The cluster will ensure that there are at least three copies of each bucket, one on each peer node, to satisfy the replication factor of 3. The cluster will also ensure that there are at least two searchable copies of each bucket, one primary and one searchable, to satisfy the search factor of