Splunk SPLK-3002 Practice Exams
Last updated on Oct 06,2026- Exam Code: SPLK-3002
- Exam Name: Splunk IT Service Intelligence Certified Admin Exam
- Certification Provider: Splunk
- Latest update: Oct 06,2026
Which of the following are the default ports that must be configured on Splunk to use ITSI?
- A . SplunkWeb (8405), SplunkD (8519), and HTTP Collector (8628)
- B . SplunkWeb (8089), SplunkD (8088), and HTTP Collector (8000)
- C . SplunkWeb (8000), SplunkD (8089), and HTTP Collector (8088)
- D . SplunkWeb (8088), SplunkD (8089), and HTTP Collector (8000)
C
Explanation:
Reference: https://splunk.github.io/docker-splunk/ARCHITECTURE.html
C is the correct answer because ITSI uses the default ports of Splunk Enterprise for its communication and data collection. SplunkWeb uses port 8000, SplunkD uses port 8089, and HTTP Event Collector uses port 8088. These ports can be changed if needed, but they must match the configuration of Splunk Enterprise.
Reference: Ports used by ITSI
What are valid considerations when designing an ITSI Service? (Choose all that apply.)
- A . Service access control requirements for ITSI Team Access should be considered, and appropriate teams provisioned prior to creating the ITSI Service.
- B . Entities, entity meta-data, and entity rules should be planned carefully to support the service design and configuration.
- C . Services, entities, and saved searches are stored in the ITSI app, while events created by KPI execution are stored in the itsi_summary index.
- D . Backfill of a KPI should always be selected so historical data points can be used immediately and alerts based on that data can occur.
A, B, C
Explanation:
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/ImplementPerms
A, B, and C are correct answers because service access control requirements for ITSI Team Access should be considered before creating the ITSI Service, as different teams may have different permissions and views of the service data. Entities, entity meta-data, and entity rules should also be planned carefully to support the service design and configuration, as they determine how ITSI maps data sources to services and KPIs. Services, entities, and saved searches are stored in the ITSI app, while events created by KPI execution are stored in the itsi_summary index for faster retrieval and analysis.
Reference: ITSI service design best practices, Overview of ITSI indexes
Which of the following is a recommended best practice for ITSI installation?
- A . ITSI should not be installed on search heads that have Enterprise Security installed.
- B . Before installing ITSI, make sure the Common Information Model (CIM) is installed.
- C . Install the Machine Learning Toolkit app if anomaly detection must be configured.
- D . Install ITSI on one search head in a search head cluster and migrate the configuration bundle to other search heads.
A
Explanation:
One of the recommended best practices for Splunk IT Service Intelligence (ITSI) installation is to avoid installing ITSI on search heads that already have Splunk Enterprise Security (ES) installed. This recommendation stems from potential resource conflicts and performance issues that can arise when both resource-intensive applications are deployed on the same instance. Both ITSI and ES are complex applications that require significant system resources to function effectively, and running them concurrently on the same search head can lead to degraded performance, conflicts in resource allocation, and potential stability issues. It’s generally advised to segregate these applications onto separate Splunk instances to ensure optimal performance and stability for both platforms.
Which of the following are characteristics of ITSI service dependencies? (select all that apply)
- A . If a primary service has a dependent service KPI and the KPI’s importance level is changed, the dependency is broken.
- B . It is best practice to use the dependent service’s built-in ‘ServiceHealthScore’ KPI to reflect impact to the primary service.
- C . Setting the dependent service KPI importance level will be treated as any other KPI in the primary service’s health score.
- D . Impactful dependent services should only be configured to one primary service to avoid false negatives in Multi KPI Alerts.
BC
Explanation:
In the context of Splunk IT Service Intelligence (ITSI), service dependencies allow for the modeling of relationships between services, where the health of one service (dependent) can affect the health of another (primary).
B) It is best practice to use the dependent service’s built-in ‘ServiceHealthScore’ KPI to reflect impact to the primary service: Utilizing the ‘ServiceHealthScore’ KPI of a dependent service as part of the primary service’s health calculation is a recommended practice. This approach ensures that changes in the health of the dependent service directly influence the primary service’s overall health score, providing a more holistic view of service health within the IT environment.
C) Setting the dependent service KPI importance level will be treated as any other KPI in the primary service’s health score: When a dependent service’s KPI is incorporated into a primary service, the importance level assigned to this KPI is factored into the primary service’s overall health score calculation just like any other KPI. This means that the impact of the dependent service on the primary service can be weighted according to the business significance of the relationship between the services.
The other options are not accurate representations of ITSI service dependencies. Changes in KPI importance levels do not break dependencies, and there is no restriction on configuring impactful dependent services to only one primary service, as dependencies can be complex and multi-layered across various services.
Besides creating notable events, what are the default alert actions a correlation search can execute? (Choose all that apply.)
- A . Ping a host.
- B . Send email.
- C . Include in RSS feed.
- D . Run a script.
B, C, D
Explanation:
Throttling applies to any correlation search alert type, including notable events and actions (RSS feed, email, run script, and ticketing).
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/EA/ConfigCS
B, C, and D are correct answers because they are the default alert actions that a correlation search can execute besides creating notable events. You can configure a correlation search to send an email, include the results in an RSS feed, or run a custom script when the search matches a defined pattern. Ping a host is not a default alert action for correlation searches.
Reference: Configure correlation search settings in ITSI
What is the main purpose of service templates in ITSI?
- A . To generate reports
- B . To automate incident response
- C . To standardize service configurations
- D . To monitor network traffic
How do you automatically restrict a KPI to only the entities in its service, and generate KPI values for each entity?
- A . Select “Yes” for both “Split by Entity” and “Filter to Entities in Service”.
- B . Select “No” for “Split by Entity” and “Yes” for “Filter to Entities in Service”.
- C . Select “Yes” for “Split by Entity” and “No” for “Filter to Entities in Service”.
- D . Select “No” for both “Split by Entity” and “Filter to Entities in Service”.
A
Explanation:
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/BaseSearch
A is the correct answer because selecting “Yes” for both “Split by Entity” and “Filter to Entities in Service” allows you to automatically restrict a KPI to only the entities in its service and generate KPI values for each entity. Split by Entity splits the KPI search results by entity alias fields and calculates a separate KPI value for each entity. Filter to Entities in Service filters out any entities that are not part of the service from the KPI search results. This way, you can ensure that your KPI reflects only the relevant entities for your service and provides granular information for each entity.
Reference: [Configure KPI settings in ITSI]
What is the minimum number of entities a KPI must be split by in order to use Entity Cohesion anomaly detection?
- A . 3
- B . 4
- C . 5
- D . 2
D
Explanation:
For Entity Cohesion anomaly detection in Splunk IT Service Intelligence (ITSI), the minimum number of entities a KPI must be split by is 2. Entity Cohesion as a method of anomaly detection focuses on identifying anomalies based on the deviation of an entity’s behavior in comparison to other entities within the same group or cohort. By requiring a minimum of only two entities, ITSI allows for the comparison of entities to detect significant deviations in one entity’s performance or behavior, which could indicate potential issues. This method leverages the idea that entities performing similar functions or within the same service should exhibit similar patterns of behavior, and significant deviations could be indicative of anomalies. The low minimum requirement of two entities ensures that this powerful anomaly detection feature can be utilized even in smaller environments.
Which of the following is a characteristic of base searches?
- A . Search expression, entity splitting rules, and thresholds are configured at the base search level.
- B . It is possible to filter to entities assigned to the service for calculating the metrics for the service’s KPIs.
- C . The fewer KPIs that share a common base search, the more efficiency a base search provides, and anomaly detection is more efficient.
- D . The base search will execute whether or not a KPI needs it.
B
Explanation:
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/BaseSearch
A base search is a search definition that can be shared across multiple KPIs that use the same data source. Base searches can improve search performance and reduce search load by consolidating multiple similar KPIs. One of the characteristics of base searches is that it is possible to filter to entities assigned to the service for calculating the metrics for the service’s KPIs. This means that you can use entity filtering rules to specify which entities are relevant for each KPI based on the base search results.
Reference: Create KPI base searches in ITSI, [Filter entities for KPIs based on base searches]
Which of the following is part of setting up a new aggregation policy?
- A . Filtering criteria
- B . Policy version
- C . Review order
- D . Module rules
A
Explanation:
When setting up a new aggregation policy in Splunk IT Service Intelligence (ITSI), one of the crucial components is defining the filtering criteria. This aspect of the aggregation policy determines which events should be included in the aggregation based on specific conditions or attributes. The filtering criteria can be based on various event fields such as severity, source, event type, and other custom fields relevant to the organization’s monitoring strategy. By specifying the filtering criteria, ITSI administrators can ensure that the aggregation policy is applied only to the pertinent events, thus facilitating more targeted and effective event management and reducing noise in the operational environment. This helps in organizing and prioritizing events more efficiently, enhancing the overall incident management process within ITSI.