Splunk SPLK-3002 Practice Exams
Last updated on Oct 06,2026- Exam Code: SPLK-3002
- Exam Name: Splunk IT Service Intelligence Certified Admin Exam
- Certification Provider: Splunk
- Latest update: Oct 06,2026
What effects does the KPI importance weight of 11 have on the overall health score of a service?
- A . At least 10% of the KPIs will go critical.
- B . Importance weight is unused for health scoring.
- C . The service will go critical.
- D . It is a minimum health indicator KPI.
B
Explanation:
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/KPIImportance#:~:text=ITSI%20considers%20KPIs%20that%20have,other%20KPIs%20in%20the%20service
The KPI importance weight is a value that indicates how much a KPI contributes to the overall health score of a service. The importance weight can range from 1 (lowest) to 10 (highest).
The statement that applies when configuring a KPI importance weight of 11 is:
B) Importance weight is unused for health scoring. This is true because an importance weight of 11 is invalid and cannot be used for health scoring. The maximum value for importance weight is 10.
The other statements do not apply because:
A) At least 10% of the KPIs will go critical. This is not true because an importance weight of 11 does not affect the severity level of any KPIs.
C) The service will go critical. This is not true because an importance weight of 11 does not affect the health score or status of any service.
D) It is a minimum health indicator KPI. This is not true because an importance weight of 11 does not indicate anything about the minimum health level of a KPI.
Reference: Set KPI importance values in ITSI
When creating a custom deep dive, what color are services/KPIs in maintenance mode within the topology view?
- A . Gray
- B . Purple
- C . Gear Icon
- D . Blue
A
Explanation:
When creating a custom deep dive, services or KPIs that are in maintenance mode are shown in gray color in the topology view. This indicates that they are not actively monitored and do not generate alerts or notable events.
Reference: Deep Dives
To use Adaptive Threshholding, what is the minimum requirement for a set of KPI data?
- A . 14 days old.
- B . 7 days old.
- C . 30 days old.
- D . 10 days old.
B
Explanation:
To utilize Adaptive Thresholding in Splunk IT Service Intelligence (ITSI), the minimum requirement for a set of Key Performance Indicator (KPI) data is that it must be at least 7 days old. Adaptive Thresholding uses historical data to dynamically adjust thresholds based on observed patterns and trends. Having a minimum of 7 days worth of data allows the system to analyze a sufficient amount of information to identify normal ranges and variances in KPI behavior, thereby setting more accurate and contextually relevant thresholds. This requirement ensures that the adaptive thresholds are based on a meaningful data set that reflects the typical operational conditions of the monitored services.
Which ITSI components are required before a module can be created?
- A . One or more entity import saved searches.
- B . One or more services with KPIs and their associated base searches.
- C . One or more datamodels.
- D . One or more correlation searches and their associated entities.
C
Explanation:
Before a module can be created in Splunk IT Service Intelligence (ITSI), it is essential to have one or more datamodels established. Datamodels in Splunk provide a structured format for organizing and interpreting data, which is crucial for modules within ITSI. Modules often rely on datamodels to extract, transform, and present data in a meaningful way, especially when dealing with complex datasets across various sources. Datamodels serve as the foundation for the module’s ability to categorize and analyze data efficiently, enabling the creation of KPIs, services, and visualizations that are aligned with the specific needs of the module. Having these datamodels in place ensures that the module can function correctly and provide valuable insights into the monitored IT environments.
Which of the following are deployment recommendations for ITSI? (Choose all that apply.)
- A . Deployments often require an increase of hardware resources above base Splunk requirements.
- B . Deployments require a dedicated ITSI search head.
- C . Deployments may increase the number of required indexers based on the number of KPI searches.
- D . Deployments should use fastest possible disk arrays for indexers.
A, B, C
Explanation:
You might need to increase the hardware specifications of your own Enterprise Security deployment above the minimum hardware requirements depending on your environment. Install Splunk Enterprise Security on a dedicated search head or search head cluster.
The Splunk platform uses indexers to scale horizontally. The number of indexers required in an Enterprise Security deployment varies based on the data volume, data type, retention requirements, search type, and search concurrency.
Reference: https://docs.splunk.com/Documentation/ES/latest/Install/DeploymentPlanning
A, B, and C are correct answers because ITSI deployments often require more hardware resources than base Splunk requirements due to the high volume of data ingestion and processing. ITSI deployments also require a dedicated search head that runs the ITSI app and handles all ITSI-related searches and dashboards. ITSI deployments may also increase the number of required indexers based on the number and frequency of KPI searches, which can generate a large amount of summary data.
Reference: ITSI deployment overview, ITSI deployment planning
Which of the following best describes an ITSI Glass Table?
- A . A view which displays a system topology overlaid with KPI metrics.
- B . A view which describes a topology.
- C . A dashboard which displays a system topology.
- D . A view showing KPI values in a variety of visual styles.
A
Explanation:
An ITSI Glass Table provides a customizable, high-level view that can display a system’s topology overlaid with real-time Key Performance Indicator (KPI) metrics and service health scores. This visualization tool allows users to create a visual representation of their IT infrastructure, applications, and services, integrating live data to monitor the health and performance of each component in context. The ability to overlay KPI metrics on the system topology enables IT and business stakeholders to quickly understand the operational status and health of various elements within their environment, facilitating more informed decision-making and rapid response to issues.
Which KPI base search capabilities are true? (Choose two)
- A . Allows sharing of a search among multiple KPIs
- B . Runs independently of services
- C . Can only be edited by admin users
- D . Automatically archives data older than 30 days
Which of the following items describe ITSI Backup and Restore functionality? (Choose all that apply.)
- A . A pre-configured default ITSI backup job is provided that can be modified, but not deleted.
- B . ITSI backup is inclusive of KV Store, ITSI Configurations, and index dependencies.
- C . kvstore_to_json.py can be used in scripts or command line to backup ITSI for full or partial backups.
- D . ITSI backups are stored as a collection of JSON formatted files.
C, D
Explanation:
ITSI provides a kvstore_to_json.py script that lets you backup/restore ITSI configuration data, perform bulk service KPI operations, apply time zone offsets for ITSI objects, and regenerate KPI search schedules.
When you run a backup job, ITSI saves your data to a set of JSON files compressed into a single ZIP file.
Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/kvstorejson https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/BackupandRestoreITSIconfig
C and D are correct answers because ITSI backup and restore functionality uses kvstore_to_json.py as a command line script or as part of custom scripts to backup ITSI data for full or partial backups. ITSI backups are also stored as a collection of JSON formatted files that contain KV store objects such as services, KPIs, glass tables, etc. A is not a correct answer because there is no pre-configured default ITSI backup job provided. You can create your own backup jobs or use the command line script or custom scripts to backup ITSI data. B is not a correct answer because ITSI backup is not inclusive of index dependencies. ITSI backup only includes KV store objects and optionally some .conf files. You need to use other methods to backup index data.
Reference: [Overview of backing up and restoring ITSI KV store data], [Create a full backup of ITSI], [Create a partial backup of ITSI]
Which of the following is a problem requiring correction in ITSI?
- A . Two or more entities with the same service ID.
- B . Two or more entities with the same entity ID.
- C . Two or more entities with the same value in a single alias field.
- D . Two or more entities with the same entity key value in any info field.
C
Explanation:
In Splunk IT Service Intelligence (ITSI), entities represent infrastructure components, applications, or other elements that are monitored. Each entity is uniquely identified by its entity ID, and entities can be associated with one or more services through the concept of aliases. A problem arises when two or more entities have the same value in a single alias field because aliases are used to match events to entities in ITSI. If multiple entities share the same alias value, ITSI might incorrectly associate data with the wrong entity, leading to inaccurate monitoring and analytics. This scenario requires correction to ensure that each alias uniquely identifies a single entity, thereby maintaining the integrity of the monitoring and analysis process within ITSI. The uniqueness of service IDs, entity IDs, and entity key values in info fields is also important but does not typically present the same level of issue as duplicate values in an alias field.
Which of the following describes enabling smart mode for an aggregation policy?
- A . Configure C> Policies C> Smart Mode C> Enable, select “fields”, click “Save”
- B . Enable grouping in Notable Event Review, select “Smart Mode”, select “fields”, and click “Save”
- C . Edit the aggregation policy, enable smart mode, select fields to analyze, click “Save”
- D . Edit the notable event view, enable smart mode, select “fields”, and click “Save”
C
Explanation: