When in maintenance mode, which of the following is accurate?
A
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/EA/REBestPractice
When must a service define entity rules?
A
Explanation:
Provide a value to filter the service to a specific set of entities. These entity rule values are meant to
be custom for each service.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/EntityRules
Which of the following is a valid type of Multi-KPI Alert?
C
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/MKA
When installing ITSI to support a Distributed Search Architecture, which of the following items apply?
(Choose all that apply.)
A
Explanation:
CopySA-IndexCreationto$SPLUNK_HOME/etc/apps/on all individual indexers in your environment.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/Install/InstallSHC
Which of the following items describe ITSI Backup and Restore functionality? (Choose all that apply.)
C, D
Explanation:
ITSI provides akvstore_to_json.pyscript that lets you backup/restore ITSI configuration data,
perform bulk service KPI operations, apply time zone offsets for ITSI objects, and regenerate KPI
search schedules.
When you run a backup job, ITSI saves your data to a set of JSON files compressed into a single ZIP
file.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/kvstorejson
https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/BackupandRestoreITSIconfig
How do you automatically restrict a KPI to only the entities in its service, and generate KPI values for
each entity?
A
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/BaseSearch
There are two departments using ITSI. Finance and Sales. Analysts in each department should not be
allowed to see each others services. What are the role configuration steps required to accomplish
this?
C
For which ITSI function is it a best practice to use a 15-30 minute time buffer?
C
Explanation:
It's a best practice to schedule maintenance windows with a 15- to 30-minute time buffer before and
after you start and stop your maintenance work. This gives the system an opportunity to catch up
with the maintenance state and reduces the chances of ITSI generating false positives during
maintenance operations.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/AboutMW
Which of the following is a good use case regarding defining entities for a service?
A
Explanation:
Define entities before creating services. When you configure a service, you can specify entity
matching rules based on entity aliases that automatically add the entities to your service.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/Entity/About
Which of the following are the default ports that must be configured on Splunk to use ITSI?
C
Reference:
https://splunk.github.io/docker-splunk/ARCHITECTURE.html
Which of the following describes enabling smart mode for an aggregation policy?
A
Explanation:
1. From the ITSI main menu, clickConfiguration>Notable Event Aggregation Policies.
2. Select a custom policy or the Default Policy.
3. Under Smart Mode grouping, enableSmart Mode.
4. ClickSelect fields. A dialog displays the fields found in your notable events from the last 24 hours.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/EA/SmartMode
Which of the following best describes a default deep dive?
D
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/DeepDives
Which index contains ITSI Episodes?
C
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/IndexOverview
In maintenance mode, which features of KPIs still function?
A
Explanation:
It's a best practice to schedule maintenance windows with a 15- to 30-minute time buffer before and
after you start and stop your maintenance work. This gives the system an opportunity to catch up
with the maintenance state and reduces the chances of ITSI generating false positives during
maintenance operations.
Reference:
https://docs.splunk.com/Documentation/ITSI/4.10.2/Configure/AboutMW
Within a correlation search, dynamic field values can be specified with what syntax?
A
Reference:
https://docs.splunk.com/Documentation/Splunk/8.2.2/Search/Searchindexes