A three-node search head cluster is skipping a large number of searches across time.
What should be done to increase scheduled search capacity on the search head cluster?
정답:
Question No : 8
In an existing Splunk environment, the new index buckets that are created each day are about half the size of the incoming data. Within each bucket, about 30% of the space is used for rawdata and about 70% for index files.
What additional information is needed to calculate the daily disk consumption, per indexer, if indexer clustering is implemented?
정답:
Question No : 9
The guidance Splunk gives for estimating size on for syslog data is 50% of original data size.
How does this divide between files in the index?
Indexing is slow and real-time search results are delayed in a Splunk environment with two indexers and one search head. There is ample CPU and memory available on the indexers.
Which of the following is most likely to improve indexing performance?
정답:
Question No : 11
Which of the following commands is used to clear the KV store?
When adding or rejoining a member to a search head cluster, the following error is displayed:
Error pulling configurations from the search head cluster captain; consider performing a destructiveconfiguration resync on this search head cluster member.
What corrective action should be taken?
정답:
Question No : 13
Which Splunk server role regulates the functioning of indexer cluster?