SPLK-3003 Core Certified Consultant Practice Questions
Prepare for SPLK-3003 with more than an answer.
- Exam fee
- $130 USD
- Level
- Expert
- Valid for
- 3 years
Domains covered on the exam 9
- Deploying Splunk10%
- Monitoring Console8%
- Access and Roles10%
- Data Collection15%
- Indexing14%
- Search15%
- Configuration Management8%
- Indexer Clustering18%
- Search Head Clustering8%
- 1
When defining data retention policies in
indexes.conf, what is the purpose of themaxTotalDataSizeMBattribute?Show answer details
Correct answer: B
The
maxTotalDataSizeMBattribute in an index stanza defines the maximum size the index can reach on a single peer/indexer. Once this size is exceeded, Splunk will start freezing the oldest (coldest) buckets to make space, enforcing the retention policy based on size. - 2
A consultant needs to decommission an entire site (site2) in a 3-site indexer cluster. Which of the following is the correct high-level procedure to perform this action gracefully without data loss?
Show answer details
Correct answer: B
Splunk's procedure for decommissioning a site starts from a complete cluster whose manager is not on that site, with site replication and search factors that keep at least one copy and one searchable copy of every bucket on other sites. Move search heads and indexer-discovery forwarders to a remaining site, then run
splunk enable maintenance-modeon the manager to prevent unnecessary bucket fixing. Updateavailable_sites,site_replication_factor,site_search_factorandsite_mappings(which maps the retired site to a remaining one), and restart the manager. Runsplunk disable maintenance-modeto start fix-up on the remaining sites, thensplunk stopeach peer on the retired site and confirm that the replication and search factors are met. Maintenance mode is always cluster-wide on the manager, never per peer. Buckets that existed on those peers before they joined the cluster are lost. - 3
An administrator needs to create a custom Splunk role for a team of security analysts. The role must let them run searches, but must not let them perform administrative tasks such as editing configurations, managing users or restarting Splunk. Which capability must be assigned to this role?
Show answer details
Correct answer: E
The
searchcapability "lets a user run a search", which is the one capability this role needs. Which indexes the analysts can search is set separately with the role's allowed indexes (srchIndexesAllowed), not with a capability.admin_all_objects(access to all objects),edit_user(manage users) andrest_properties_set(edit the services/properties endpoint) are administrative.accelerate_datamodelonly lets a user enable or disable data model acceleration and is not needed to run searches. - 4
In the context of the Splunk data pipeline, what is the primary difference between the 'parsing' queue and the 'agg' queue?
Show answer details
Correct answer: B
On the instance that parses data (an indexer or a heavy forwarder), the parsing function consists of three pipelines: parsing, merging and typing. Data from inputs enters the parsingQueue; the parsing pipeline does UTF-8 decoding, line breaking (LINE_BREAKER) and header handling. The aggQueue (aggregation queue) feeds the merging pipeline, whose aggregator processor merges lines into multi-line events and extracts timestamps. props.conf, for example, describes
DATETIME_CONFIG = CURRENTas the time the event "passed through the aggregator processor". Regex transforms (TRANSFORMS-, SEDCMD, routing) run later, in the typing pipeline after the typingQueue. REPORT- field extractions are search-time and never run in these pipelines. Both queues exist wherever data is parsed, not on separate tiers. - 5
A consultant needs to ensure that if a single indexer in a 3-peer cluster fails, no data is lost AND all data remains fully searchable without any degradation in search performance. What are the minimum
server.confsettings on the cluster master that meet this objective?graph TD subgraph IndexerCluster [3 Peers] IDX1[Indexer 1] IDX2[Indexer 2] IDX3[Indexer 3] end subgraph Requirement1 [No Data Loss] R1("If IDX1 fails, data must persist") end subgraph Requirement2 [Fully Searchable] R2("If IDX1 fails, searches must complete with all data") end Master[Cluster Master] --> IndexerClusterShow answer details
Correct answer: A
replication_factor = 2keeps two copies of every bucket on different peers, so losing one peer loses no data.search_factor = 2makes both copies searchable, so when a peer fails the manager can immediately make the surviving searchable copy primary instead of first building index files for a non-searchable copy, which is what happens withsearch_factor = 1. RF=3 with SF=2 or SF=3 also meets the objective but stores more copies than necessary, so RF=2 with SF=2 is the minimum. After an unexpected failure the manager still waits for the heartbeat timeout (60 seconds by default) before it reassigns primary copies. - 6
A financial services client has a 3-site indexer cluster (NYC, LON, TOK) configured for disaster recovery. The master node, located in NYC, has
site_replication_factor = origin:1, total:2andsite_search_factor = origin:1, total:2. The LON site experiences a complete network outage. A historical search is executed from the NYC search head, which has search affinity disabled (site0). What is the expected behavior of the search results?Show answer details
Correct answer: A
On a three-site cluster,
site_replication_factor = origin:1, total:2keeps one copy on the origin site and sends the remaining copy to a site that has no copy yet, so the two copies of every bucket sit on two different sites.site_search_factor = origin:1, total:2makes both copies searchable. When LON fails, every bucket therefore still has a searchable copy in NYC or TOK. The manager detects the failure after the heartbeat timeout (60 seconds by default); until it has reassigned primacy to the surviving searchable copies, searches return partial results. Then the cluster is valid again and the search returns complete results. No copies need to be converted, because the surviving copies are already searchable. - 7
A consultant is designing a data onboarding solution for a high-volume, custom binary log format from a proprietary manufacturing system. The logs must be parsed on a Heavy Forwarder (HF) before being sent to indexers. To ensure data integrity and prevent data loss during potential HF restarts or network issues, which configuration is most critical in
outputs.confon the HF?Show answer details
Correct answer: A
useACK = trueenables indexer acknowledgment, which is disabled by default. The forwarder keeps a copy of each data block in its in-memory wait queue until the indexer confirms it has written the data to disk. If no acknowledgment arrives (the indexer goes down, its disk is full, or the network drops), the forwarder resends the block, to the next indexer when load balancing is used. This protects data in flight, though a resend after a lost ACK can create duplicates. During a forwarder shutdown it waits up toackTimeoutOnShutdown(30 s) for outstanding ACKs.compressed,autoLBFrequencyandsendCookedData = falsedo not protect against data loss. - 8
A large retail company is using a 5-node Search Head Cluster (SHC). During a major holiday sale, users report that dashboards are intermittently failing to load and saved searches are being skipped. A review of
splunkd.logon the SHC members reveals messages related to KV Store contention and replication failures. The consultant suspects that a high frequency of lookups and summary updates from multiple apps are overwhelming the KV Store. Which of the following actions represents a robust, long-term solution to this problem?Show answer details
Correct answer: E
In a search head cluster every KV store write is delegated to the KV store captain, while reads stay local. Write-heavy apps therefore load one KV store that the whole cluster shares, and adding members does not spread that write load. Moving the apps with heavy KV store use to their own, smaller search head cluster gives them a separate KV store and removes their contention from the primary cluster. Moving high-write lookups to CSV goes against Splunk guidance: CSV lookups suit files that are small or rarely modified and need a full rewrite for every edit, while KV store lookups suit large or frequently updated tables.
splunk clean kvstoredeletes KV store data and is meant for resynchronization or restore, and search concurrency settings do not address KV store contention. - 9
A consultant is optimizing search performance. They have identified several inefficient searches that use
joinwith a large result set. They plan to replace these with thestatscommand. Which of the following is a primary advantage of usingstatsoverjoinfor correlating data from multiple sourcetypes?Show answer details
Correct answer: D
Splunk recommends
stats(ortransaction) overjoinandappendin most cases. The usual rewrite is one search that retrieves every sourcetype (for examplesourcetype=a OR sourcetype=b) followed bystats ... by, so the events are fetched once and correlated in a single pass.joinmust run a separate subsearch, and by default only 50,000 right-side rows can be joined, within 60 seconds ([join] subsearch_maxoutandsubsearch_maxtimein limits.conf), so large correlations are truncated.statsis a transforming command, not a streaming one. Reading accelerated summaries is whattstatsdoes, andstatsoutputs a results table, not_rawevents. - 10
During a Splunk deployment, a client requires that data from their PCI-compliant systems be stored in a specific, encrypted index with a 365-day retention policy, while all other data goes to a general index with a 90-day retention. Both data types arrive on the same port of a Heavy Forwarder. What is the most appropriate method to route this data to the correct indexes?
Show answer details
Correct answer: A
The correct way to route events to different indexes based on their content is at parse time on a Heavy Forwarder or on the Indexers. This is achieved by defining a stanza in
props.confthat applies aTRANSFORMS-class. This class then points to a stanza intransforms.confwhich uses a regular expression (REGEX) to match event patterns and sets theDEST_KEYto_MetaData:Indexwith theFORMATset to the target index name (e.g.,pci_index). This ensures events are written to the correct index upon arrival.
