Splunk SPLK-3002 Practice Exams
Last updated on Oct 06,2026- Exam Code: SPLK-3002
- Exam Name: Splunk IT Service Intelligence Certified Admin Exam
- Certification Provider: Splunk
- Latest update: Oct 06,2026
Which glass table feature can be used to toggle displaying KPI values from more than one service on a single widget?
- A . Service templates.
- B . Service dependencies.
- C . Ad-hoc search.
- D . Service swapping.
D
Explanation:
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/Visualizations#collapseDesktop8 A glass table is a visualization tool that allows you to monitor the interrelationships and dependencies across your IT and business services. You can add metrics like KPIs, ad hoc searches, and service health scores that update in real time against a background that you design. One of the features of glass tables is service swapping, which enables you to toggle displaying KPI values from more than one service on a single widget. You can use service swapping to compare metrics across different services without creating multiple glass tables or widgets.
Reference: Overview of the glass table editor in ITSI, [Configure service swapping on glass tables]
Which of the following is a recommended best practice for service and glass table design?
- A . Plan and implement services first, then build detailed glass tables.
- B . Always use the standard icons for glass table widgets to improve portability.
- C . Start with base searches, then services, and then glass tables.
- D . Design glass tables first to discover which KPIs are important.
A
Explanation:
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/GTOverview
A is the correct answer because it is recommended to plan and implement services first, then build detailed glass tables that reflect the service hierarchy and dependencies. This way, you can ensure that your glass tables provide accurate and meaningful service-level insights. Building glass tables first might lead to unnecessary or irrelevant KPIs that do not align with your service goals.
Reference: Splunk IT Service Intelligence Service Design Best Practices
Which of the following is the best use case for configuring a Multi-KPI Alert?
- A . Comparing content between two notable events.
- B . Using machine learning to evaluate when data falls outside of an expected pattern.
- C . Comparing anomaly detection between two KPIs.
- D . Raising an alert when one or more KPIs indicate an outage is occurring.
D
Explanation:
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/MKA
A multi-KPI alert is a type of correlation search that is based on defined trigger conditions for two or more KPIs. When trigger conditions occur simultaneously for each KPI, the search generates a notable event .
For example, you might create a multi-KPI alert based on two common KPIs: CPU load percent and web requests. A sudden simultaneous spike in both CPU load percent and web request KPIs might indicate a DDOS (Distributed Denial of Service) attack. Multi-KPI alerts can bring such trending behaviors to your attention early, so that you can take action to minimize any impact on performance. Multi-KPI alerts are useful for correlating the status of multiple KPIs across multiple services. They help you identify causal relationships, investigate root cause, and provide insights into behaviors across your infrastructure. The best use case for configuring a multi-KPI alert is to raise an alert when one or more KPIs indicate an outage is occurring, such as when the service health score drops below a certain threshold or when multiple KPIs have critical severity levels.
Reference: Create multi-KPI alerts in ITSI
After a notable event has been closed, how long will the meta data for that event remain in the KV Store by default?
- A . 6 months.
- B . 9 months.
- C . 1 year.
- D . 3 months.
A
Explanation:
By default, notable event metadata is archived after six months to keep the KV store from growing too large.
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/EA/TrimNECollections
Which step is required to install ITSI on a single Search Head?
- A . Untar the ITSI package in <splunk home>/etc/apps
- B . Run splunk_apply shcluster-bundle
- C . Use the Splunk -> Manage Apps Dashboard to download and install.
- D . All of the above.
C
Explanation:
To install Splunk IT Service Intelligence (ITSI) on a single Search Head, one of the straightforward methods is to use the Splunk Web interface, specifically the "Manage Apps" dashboard, to download and install ITSI. This method is user-friendly and does not require manual file handling or command-line operations. By navigating to "Manage Apps" in the Splunk Web interface, users can find ITSI in the app repository or upload the ITSI installation package if it has been downloaded previously. From there, the installation process is initiated through the Splunk Web interface, simplifying the setup process. This approach ensures that the installation follows Splunk’s standard app installation procedures, helping to avoid common installation errors and ensuring that ITSI is correctly integrated into the Splunk environment.
What is the default importance value for dependent services’ health scores?
- A . 11
- B . 1
- C . Unassigned
- D . 10
D
Explanation:
By default, impacting service health scores have an importance value of 11.
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/Dependencies
A service template is a predefined set of KPIs and entity rules that you can apply to a service or a group of services. A service template helps you standardize the configuration and monitoring of similar services across your IT environment. A service template can also include dependent services, which are services that are required for another service to function properly .
For example, a web server service might depend on a database service and a network service.
The default importance value for dependent services’ health scores is:
D) 10. This is true because the importance value indicates how much a dependent service contributes to the health score of the parent service. The default value is 10, which means that the dependent service has the highest impact on the parent service’s health score. You can change the importance value of a dependent service in the service template settings.
The other options are not correct because:
A) 11. This is not true because 11 is an invalid value for importance. The valid range is from 1 (lowest) to 10 (highest).
B) 1. This is not true because 1 is the lowest value for importance, not the default value. A value of 1 means that the dependent service has the lowest impact on the parent service’s health score.
C) Unassigned. This is not true because every dependent service has an assigned importance value, which defaults to 10.
Reference: Create and manage service templates in ITSI, Set KPI importance values in ITSI
ITSI Saved Search Scheduling is configured to use realtime_schedule = 0.
Which statement is accurate about this configuration?
- A . If this value is set to 0, the scheduler bases its determination of the next scheduled search execution time on the current time.
- B . If this value is set to 0, the scheduler bases its determination of the next scheduled search on the last search execution time.
- C . If this value is set to 0, the scheduler may skip scheduled execution periods.
- D . If this value is set to 0, the scheduler might skip some execution periods to make sure that the scheduler is executing the searches running over the most recent time range.
B
Explanation:
ITSI Saved Search Scheduling is a feature that allows you to schedule searches that run periodically to populate the data for your KPIs. You can configure various settings for your scheduled searches, such as the search frequency, the time range, the cron expression, and so on. One of the settings is realtime_schedule, which controls the way the scheduler computes the next execution time of a scheduled search.
The statement that is accurate about this configuration is:
B) If this value is set to 0, the scheduler bases its determination of the next scheduled search on the last search execution time. This is called continuous scheduling. If set to 0, the scheduler never skips scheduled execution periods. However, the execution of the saved search might fall behind depending on the scheduler’s load. Use continuous scheduling whenever you enable the summary index option.
The other statements are not accurate because:
A) If this value is set to 0, the scheduler bases its determination of the next scheduled search execution time on the current time. This is not true because this is what happens when the value is set to 1, not 0.
C) If this value is set to 0, the scheduler may skip scheduled execution periods. This is not true because this is what happens when the value is set to 1, not 0.
D) If this value is set to 0, the scheduler might skip some execution periods to make sure that the scheduler is executing the searches running over the most recent time range. This is not true because this is what happens when the value is set to 1, not 0.
Reference: Create KPI base searches in ITSI, Rrealtime_schedule in SavedSearches.conf
How can Service Now incidents be created automatically when a Multi-KPI alert triggers? (select all that apply)
- A . By creating a custom etc/apps/SA-lTOA/workflow_rules. conf
- B . By linking Entities to Service-Now configuration items.
- C . By creating a notable event aggregation policy with a SNOW incident action.
- D . By editing the associated correlation search and specifying an alert action.
CD
Explanation:
To automatically create ServiceNow incidents when a Multi-KPI alert triggers in Splunk IT Service Intelligence (ITSI), the following approaches can be used:
C) By creating a notable event aggregation policy with a ServiceNow (SNOW) incident action: ITSI allows the creation of notable event aggregation policies that can specify actions to be taken when certain conditions are met. One of these actions can be the creation of an incident in ServiceNow, directly linking the alerting mechanism in ITSI with incident management in ServiceNow.
D) By editing the associated correlation search and specifying an alert action: Correlation searches in ITSI are used to identify patterns or conditions that signify notable events. These searches can be configured to include alert actions, such as creating a ServiceNow incident, whenever the search conditions are met. This direct integration ensures that incidents are automatically generated in ServiceNow, based on the specific criteria defined in the correlation search.
Options A and B are not standard practices for integrating ITSI with ServiceNow for automatic incident creation. The configuration typically involves setting up actionable alert mechanisms within ITSI that are specifically designed to integrate with external systems like ServiceNow.
After ITSI is initially deployed for the operations department at a large company, another department would like to use ITSI but wants to keep their information private from the operations group.
How can this be achieved?
- A . Create service templates for each group and create the services from the templates.
- B . Create teams for each department and assign KPIs to each team.
- C . Create services for each group and set the permissions of the services to restrict them to each group.
- D . Create teams for each department and assign services to the teams.
D
Explanation:
In Splunk IT Service Intelligence (ITSI), creating teams for each department and assigning services to those teams is an effective way to segregate data and ensure that information remains private between different groups within an organization. Teams in ITSI provide a mechanism for role-based access control, allowing administrators to define which users or groups have access to specific services, KPIs, and dashboards. By setting up teams corresponding to each department and then assigning services to these teams, ITSI can accommodate multi-departmental use within the same instance while maintaining strict access controls. This ensures that each department can only view and interact with the data and services relevant to their operations, preserving confidentiality and data integrity across the organization.
In Episode Review, what is the result of clicking an episode’s Acknowledge button?
- A . Assign the current user as owner.
- B . Change status from New to Acknowledged.
- C . Change status from New to In Progress and assign the current user as owner.
- D . Change status from New to Acknowledged and assign the current user as owner.
D
Explanation:
When an episode warrants investigation, the analyst acknowledges the episode, which moves the status from New to In Progress.
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/EA/EpisodeOverview
An episode represents a disruption of service operation causing impact to business operations. It is a deduplicated group of notable events occurring as part of a larger sequence, or an incident or period considered in isolation. In Episode Review, you can manage the episodes and their statuses using various actions. One of the actions is Acknowledge, which changes the status of an episode from New to Acknowledged and assigns the current user as the owner. This action indicates that someone is working on resolving the episode and prevents duplicate efforts from other users.
Reference: Overview of Episode Review in ITSI, [Episode actions in Episode Review]