New Year Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

SPLK-3002 Questions and Answers

Question # 6

How should entities be handled during the data audit phase of requirements gathering?

A.

Entity meta-data for info and aliases should be identified and recorded as requirements.

B.

Entities should be noted based upon Service KPI requirements such as 'by host' or 'by product line'.

C.

Entities must be identified for every Service KPI defined and recorded in requirements.

D.

Entities identified should be included in the entity filtering requirements, such as 'by processld' or 'by host'.

Full Access
Question # 7

What is the minimum number of entities a KPI must be split by in order to use Entity Cohesion anomaly detection?

A.

3

B.

4

C.

5

D.

2

Full Access
Question # 8

In maintenance mode, which features of KPIs still function?

A.

KPI searches will execute but will be buffered until the maintenance window is over.

B.

KPI searches still run during maintenance mode, but results go to itsi_maintenance_summary index.

C.

New KPIs can be created, but existing KPIs are locked.

D.

KPI calculations and threshold settings can be modified.

Full Access
Question # 9

Which of the following describes default deep dives?

A.

Are manually generated and can be accessed via the Service Analyzer.

B.

Include all KPIs of all services.

C.

Are auto-generated and can be accessed via the Service Analyzer.

D.

Include health scores of all services.

Full Access
Question # 10

Which of the following items describe ITSI teams? (select all that apply)

A.

Teams should have itoa admin roles added with read-only permissions for services and entities.

B.

Services should be assigned to the 'global' team if all users need access to it.

C.

By default, all services are owned by the built-in 'global' team and administered by the 'itoa_admin' role.

D.

A new team admin role should be created for each team. The new role should inherit the 'itoa_team_admin' role.

Full Access
Question # 11

There are two Smart Mode configuration settings that control how fields affect grouping. Which of these is correct?

A.

Text deviation and category deviation.

B.

Text similarity and category deviation.

C.

Text similarity and category similarity.

D.

Text deviation and category similarity.

Full Access
Question # 12

What is the main purpose of the service analyzer?

A.

Display a list of All Services and Entities.

B.

Trigger external alerts based on threshold violations.

C.

Allow Analysts to add comments to Alerts.

D.

Monitor overall Service and KPI status.

Full Access
Question # 13

Which of the following items describe ITSI Deep Dive capabilities? (Choose all that apply.)

A.

Comparing a service’s notable events over a time period.

B.

Visualizing one or more Service KPIs values by time.

C.

Examining and comparing alert levels for KPIs in a service over time.

D.

Comparing swim lane values for a slice of time.

Full Access
Question # 14

How can admins manually control groupings of notable events?

A.

Correlation searches.

B.

Multi-KPI alerts.

C.

notable_event_grouping.conf

D.

Aggregation policies.

Full Access
Question # 15

Which of the following is the best use case for configuring a Multi-KPI Alert?

A.

Comparing content between two notable events.

B.

Using machine learning to evaluate when data falls outside of an expected pattern.

C.

Comparing anomaly detection between two KPIs.

D.

Raising an alert when one or more KPIs indicate an outage is occurring.

Full Access
Question # 16

Anomaly detection can be enabled on which one of the following?

A.

KPI

B.

Multi-KPI alert

C.

Entity

D.

Service

Full Access
Question # 17

When working with a notable event group in the Notable Events Review dashboard, which of the following can be set at the individual or group level?

A.

Service, status, owner.

B.

Severity, status, owner.

C.

Severity, comments, service.

D.

Severity, status, service.

Full Access
Question # 18

When troubleshooting KPI search performance, which search names in job activity identify base searches?

A.

Indicator - XXXX - Base Search

B.

Indicator - Shared - xxxx - ITSI Search

C.

Indicator - Base - xxxx - ITSI Search

D.

Indicator - Base - XXXX - Shared Search

Full Access
Question # 19

Which capabilities are enabled through “teams”?

A.

Teams allow searches against the itsi_summary index.

B.

Teams restrict notable event alert actions.

C.

Teams restrict searches against the itsi_notable_audit index.

D.

Teams allow restrictions to service content in UI views.

Full Access
Question # 20

When a KPI's aggregate value is calculated, which function is called?

A.

stats

B.

tstats

C.

fieldsummary

D.

eval

Full Access
Question # 21

What is the default importance value for dependent services’ health scores?

A.

11

B.

1

C.

Unassigned

D.

10

Full Access
Question # 22

Which of the following is a recommended best practice for ITSI installation?

A.

ITSI should not be installed on search heads that have Enterprise Security installed.

B.

Before installing ITSI, make sure the Common Information Model (CIM) is installed.

C.

Install the Machine Learning Toolkit app if anomaly detection must be configured.

D.

Install ITSI on one search head in a search head cluster and migrate the configuration bundle to other search heads.

Full Access
Question # 23

Which of the following describes enabling smart mode for an aggregation policy?

A.

Configure –> Policies –> Smart Mode –> Enable, select “fields”, click “Save”

B.

Enable grouping in Notable Event Review, select “Smart Mode”, select “fields”, and click “Save”

C.

Edit the aggregation policy, enable smart mode, select fields to analyze, click “Save”

D.

Edit the notable event view, enable smart mode, select “fields”, and click “Save”

Full Access
Question # 24

What effects does the KPI importance weight of 11 have on the overall health score of a service?

A.

At least 10% of the KPIs will go critical.

B.

Importance weight is unused for health scoring.

C.

The service will go critical.

D.

It is a minimum health indicator KPI.

Full Access
Question # 25

Which anomaly detection algorithm is included within ITSI?

A.

Entity cohesion

B.

Standard deviation

C.

Linear regression

D.

Infantile regression

Full Access
Question # 26

Within a correlation search, dynamic field values can be specified with what syntax?

A.

fieldname

B.

C.

%fieldname%

D.

eval(fieldname)

Full Access
Question # 27

Which index is used to store KPI values?

A.

itsi_summary_metrics

B.

itsi_metrics

C.

itsi_service_health

D.

itsi_summary

Full Access
Question # 28

To use Adaptive Threshholding, what is the minimum requirement for a set of KPI data?

A.

14 days old.

B.

7 days old.

C.

30 days old.

D.

10 days old.

Full Access