Splunk SPLK-3002 Practice Exams
Last updated on Oct 06,2026- Exam Code: SPLK-3002
- Exam Name: Splunk IT Service Intelligence Certified Admin Exam
- Certification Provider: Splunk
- Latest update: Oct 06,2026
When installing ITSI to support a Distributed Search Architecture, which of the following items apply? (Choose all that apply.)
- A . Copy SA-IndexCreation to all indexers.
- B . Copy SA-IndexCreation to the etc/apps directory on the index cluster master node.
- C . Extract installer package into etc/apps directory of the cluster deployer node.
- D . Extract ITSI app package into etc/apps directory of search head.
A
Explanation:
Copy SA-IndexCreation to $SPLUNK_HOME/etc/apps/ on all individual indexers in your environment.
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/Install/InstallSHC
A is the correct answer because when installing ITSI to support a distributed search architecture, you need to copy SA-IndexCreation to all indexers. SA-IndexCreation is an app that contains the definitions of the ITSI indexes, such as itsi_summary, itsi_tracked_alerts, itsi_grouped_alerts, etc. You need to copy this app to all indexers to ensure that they can store and search the ITSI data. B is not a correct answer because you do not need to copy SA-IndexCreation to the etc/apps directory on the index cluster master node. The index cluster master node does not store or search data, it only manages the replication and availability of data across the index cluster peers. C is not a correct answer because you do not need to extract the installer package into etc/apps directory of the cluster deployer node. The cluster deployer node is used to distribute apps and configuration updates to the search head cluster members. You need to extract the installer package into etc/shcluster/apps
directory of the cluster deployer node instead. D is not a correct answer because you do not need to extract the ITSI app package into etc/apps directory of search head. You need to extract the ITSI app package into etc/shcluster/apps directory of the cluster deployer node and use the deployer to push the app to all search head cluster members.
Reference: [Install Splunk IT Service Intelligence on a search head cluster], [Install Splunk IT Service Intelligence on an indexer cluster]
Which views would help an analyst identify that a memory usage KPI is going critical? (select all that apply)
- A . Memory KPI in a glass table.
- B . Memory panel of the OS Host Details view in the Operating System module.
- C . Memory swim lane in a Deep Dive.
- D . Service & KPI tiles in the Service Analyzer.
ABCD
Explanation:
To identify that a memory usage KPI is going critical, an analyst can leverage multiple views within Splunk IT Service Intelligence (ITSI), each offering a different perspective or level of detail:
A) Memory KPI in a glass table: A glass table can display the current status of the memory usage KPI, along with other related KPIs and services, providing a high-level overview of system health.
B) Memory panel of the OS Host Details view in the Operating System module: This specific panel within the OS Host Details view offers detailed metrics and trends related to memory usage, allowing for in-depth analysis.
C) Memory swim lane in a Deep Dive: Deep Dives allow analysts to visually track the performance and status of KPIs over time. A swim lane dedicated to memory usage can highlight periods where the KPI goes critical, along with the context of other related KPIs.
D) Service & KPI tiles in the Service Analyzer: The Service Analyzer provides a comprehensive overview of all services and their KPIs. The tiles related to memory usage can quickly alert analysts to critical conditions through color-coded indicators.
Each of these views contributes to a comprehensive monitoring strategy, enabling analysts to detect and respond to critical memory usage conditions from various analytical perspectives.
Which of the following are characteristics of service templates? (select all that apply)
- A . Service templates can be modified after services are instantiated from it.
- B . Service templates contain KPIs and KPI thresholds.
- C . Service templates can contain specific or generic entity rules.
- D . Service templates contain domain specific dashboards and deep dives.
BC
Explanation:
Service templates in Splunk IT Service Intelligence (ITSI) are designed to streamline the creation of services by providing pre-defined configurations:
B) Service templates contain KPIs and KPI thresholds: This allows for the standardized deployment of services with predefined performance indicators and their associated thresholds, ensuring consistency across similar services.
C) Service templates can contain specific or generic entity rules: These rules define how entities are associated with services created from the template, allowing for both broad and targeted applicability.
While service templates contain configurations for KPIs, thresholds, and entity rules, the ability to modify templates after services have been instantiated from them is limited. Changes to a template do not retroactively affect services already created from that template. Moreover, service templates do not inherently contain domain-specific dashboards or deep dives; these are created separately within ITSI.
Which of the following items apply to anomaly detection? (Choose all that apply.)
- A . Use AD on KPIs that have an unestablished baseline of data points. This allows the ML pattern to perform it’s magic.
- B . A minimum of 24 hours of data is needed for anomaly detection, and a minimum of 4 entities for cohesive analysis.
- C . Anomaly detection automatically generates notable events when KPI data diverges from the pattern.
- D . There are 3 types of anomaly detection supported in ITSI: adhoc, trending, and cohesive.
B, C
Explanation:
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/AD
Anomaly detection is a feature of ITSI that uses machine learning to detect when KPI data deviates from a normal pattern. The following items apply to anomaly detection:
B) A minimum of 24 hours of data is needed for anomaly detection, and a minimum of 4 entities for cohesive analysis. This ensures that there is enough data to establish a baseline pattern and compare different entities within a service.
C) Anomaly detection automatically generates notable events when KPI data diverges from the pattern. You can configure the sensitivity and severity of the anomaly detection alerts and assign them to episodes or teams.
Reference: [Anomaly Detection]
Which of the following is a good use case for creating a custom module?
- A . Modules are required to create entity and service import searches.
- B . Modules are required to be able to create custom visualizations for deep dives.
- C . Making it easy to migrate KPI base searches and related visualizations to other ITSI installations.
- D . Creating a service template to make it easy to automatically create new services during service and entity import.
C
Explanation:
Creating a custom module in Splunk IT Service Intelligence (ITSI) is particularly beneficial for the purpose of migrating KPI base searches and related visualizations to other ITSI installations. Custom modules can encapsulate a set of configurations, searches, and visualizations that are tailored to specific monitoring needs or environments. By packaging these elements into a module, it becomes easier to transfer, deploy, and maintain consistency across different ITSI instances. This modularity supports the reuse of developed components, simplifying the process of scaling and replicating monitoring setups in diverse operational contexts. The ability to migrate these components seamlessly enhances operational efficiency and ensures that best practices and custom configurations can be shared across an organization’s ITSI deployments.
How should entities be handled during the data audit phase of requirements gathering?
- A . Entity meta-data for info and aliases should be identified and recorded as requirements.
- B . Entities should be noted based upon Service KPI requirements such as ‘by host’ or ‘by product line’.
- C . Entities must be identified for every Service KPI defined and recorded in requirements.
- D . Entities identified should be included in the entity filtering requirements, such as ‘by processld’ or ‘by host’.
A
Explanation:
During the data audit phase of requirements gathering for Splunk IT Service Intelligence (ITSI), it’s crucial to identify and record the meta-data for entities, focusing on information (info) and aliases. This step involves understanding and documenting the key attributes and identifiers that describe each entity, such as host names, IP addresses, device types, or other relevant characteristics. These attributes are used to categorize and uniquely identify entities within ITSI, enabling more effective mapping of data to services and KPIs. By meticulously recording this meta-data, organizations ensure that their ITSI implementation is aligned with their specific monitoring needs and infrastructure, facilitating accurate service modeling and event management. This practice is foundational for setting up ITSI to reflect the actual IT environment, enhancing the relevance and effectiveness of the monitoring and analysis capabilities.
Where are KPI search results stored?
- A . The default index.
- B . KV Store.
- C . Output to a CSV lookup.
- D . The itsi_summary index.
D
Explanation:
Search results are processed, created, and written to the itsi_summary index via an alert action.
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/BaseSearch
D is the correct answer because KPI search results are stored in the itsi_summary index in ITSI. This index is an events index that stores the results of scheduled KPI searches. Summary indexing lets you run fast searches over large data sets by spreading out the cost of a computationally expensive report over time.
Reference: Overview of ITSI indexes
Which of the following is a best practice when configuring maintenance windows?
- A . Disable any glass tables that reference a KPI that is part of an open maintenance window.
- B . Develop a strategy for configuring a service’s notable event generation when the service’s maintenance window is open.
- C . Give the maintenance window a buffer, for example, 15 minutes before and after actual maintenance work.
- D . Change the color of services and entities that are part of an open maintenance window in the service analyzer.
C
Explanation:
It’s a best practice to schedule maintenance windows with a 15- to 30-minute time buffer before and after you start and stop your maintenance work.
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/AboutMW
A maintenance window is a period of time when a service or entity is undergoing maintenance operations or does not require active monitoring. It is a best practice to schedule maintenance windows with a 15- to 30-minute time buffer before and after you start and stop your maintenance work. This gives the system an opportunity to catch up with the maintenance state and reduces the chances of ITSI generating false positives during maintenance operations .
For example, if a server will be shut down for maintenance at 1:00PM and restarted at 5:00PM, the ideal maintenance window is 12:30PM to 5:30PM. The 15- to 30-minute time buffer is a rough estimate based on 15 minutes being the time period over which most KPIs are configured to search data and identify alert triggers.
Reference: Overview of maintenance windows in ITSI
What should be considered when onboarding data into a Splunk index, assuming that ITSI will need to use this data?
- A . Use | stats functions in custom fields to prepare the data for KPI calculations.
- B . Check if the data could leverage pre-built KPIs from modules, then use the correct TA to onboard the data.
- C . Make sure that all fields conform to CIM, then use the corresponding module to import related services.
- D . Plan to build as many data models as possible for ITSI to leverage
B
Explanation:
Reference: https://newoutlook.it/download/book/splunk/advanced-splunk.pdf
When onboarding data into a Splunk index, assuming that ITSI will need to use this data, you should consider the following:
B) Check if the data could leverage pre-built KPIs from modules, then use the correct TA to onboard the data. This is true because modules are pre-packaged sets of services, KPIs, and dashboards that are designed for specific types of data sources, such as operating systems, databases, web servers, and so on. Modules help you quickly set up and monitor your IT services using best practices and industry standards. To use modules, you need to install and configure the correct technical add-ons (TAs) that extract and normalize the data fields required by the modules.
The other options are not things you should consider because:
A) Use | stats functions in custom fields to prepare the data for KPI calculations. This is not true because using | stats functions in custom fields can cause performance issues and inaccurate results when calculating KPIs. You should use | stats functions only in base searches or ad hoc searches, not in custom fields.
C) Make sure that all fields conform to CIM, then use the corresponding module to import related services. This is not true because not all modules require CIM-compliant data sources. Some modules have their own data models and field extractions that are specific to their data sources. You should check the documentation of each module to see what data requirements and dependencies they have.
D) Plan to build as many data models as possible for ITSI to leverage. This is not true because building too many data models can cause performance issues and resource consumption in your Splunk environment. You should only build data models that are necessary and relevant for your ITSI use cases.
Reference: Overview of modules in ITSI, [Install technical add-ons for ITSI modules]
Which of the following is an advantage of an adaptive time threshold?
- A . Automatically alerting when KPI value patterns change over time.
- B . Automatically adjusting thresholds as normal KPI values change over time.
- C . Automatically adjusting to holiday schedules.
- D . Automatically predicting future degradation of KPI values over time.
B
Explanation:
An adaptive time threshold in the context of Splunk IT Service Intelligence (ITSI) refers to the capability of dynamically adjusting threshold values for Key Performance Indicators (KPIs) based on historical data trends and patterns. This feature allows thresholds to evolve as the ‘normal’ behavior of KPIs changes over time, ensuring that alerts remain relevant and reduce the likelihood of false positives or negatives. The advantage of this approach is that it accommodates for natural fluctuations in KPI values that may occur due to changes in business operations, seasonality, or other factors, without requiring manual threshold adjustments. This makes the monitoring system more resilient and responsive to actual conditions, improving the overall effectiveness of IT operations management.