SPLK-3002 Sample Questions

SPLK-3002 Sample Questions & Answers

Several areas tie for the heaviest weight: glass table configuration, managing notable events, deep dive investigations, installing and configuring ITSI, data audit and base search design, implementing services, and setting up KPIs with thresholds.

Launch the full SPLK-3002 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Anomaly Detection · Enable anomaly detection

    A media streaming company is using ITSI to monitor its video delivery service. They have a KPI for 'Video Buffering Rate'. They want to enable anomaly detection for this KPI to proactively identify unusual increases in buffering. The buffering rate has strong daily and weekly seasonal patterns. To ensure the anomaly detection algorithm is effective, what is the minimum recommended amount of historical data required for training?

    Show answer & explanation

    Correct answer: B

    For anomaly detection to be effective, especially with strong seasonal patterns, Splunk recommends a minimum of 30 days of historical data for training. This duration allows the machine learning algorithms to learn the daily and weekly patterns, establish a reliable baseline, and more accurately identify true anomalies rather than predictable peaks.

  2. Question 2Intermediate

    Investigating Issues with Deep Dives · Add and configure swim lanes

    An ITSI admin is creating a custom deep dive to troubleshoot a database performance issue. They want to correlate the 'DB CPU Utilization %' KPI with the number of 'Active DB Connections' and the raw error logs from the database server. Which combination of swim lanes would be most effective for this investigation?

    Show answer & explanation

    Correct answer: C

    This is the most effective combination. A KPI lane is best for displaying the historical trend of the 'DB CPU Utilization %' KPI. A Metric lane is appropriate for charting the ad-hoc metric of 'Active DB Connections'. An Event lane is specifically designed to display raw log events, allowing the admin to see the actual error messages from the database server at specific points in time, correlating them with the KPI and metric trends.

  3. Question 3Advanced

    Access Control · Create service level teams

    A new service named Online_Banking_Portal has been created. The administrator needs to grant a team of Banking_Ops analysts read-only access to this specific service and its KPIs, but prevent them from seeing any other services in ITSI. What is the correct sequence of steps to achieve this?

    Show answer & explanation

    Correct answer: D

    This is the correct procedure for service-level access control in ITSI. Teams are the mechanism for assigning permissions to specific services. The correct workflow is: 1) Create a team (e.g., 'Banking Services Team'). 2) Assign the specific service (Online_Banking_Portal) to this team with 'read' permissions. 3) Assign the Splunk role (Banking_Ops) that contains the users to the newly created team. This ensures the users in that role only get the permissions defined for that team on that specific service.

  4. Question 4IntermediateSelect 2

    Glass Tables · Design glass tables

    When designing a glass table for a Network Operations Center (NOC), the primary goal is to provide an at-a-glance, high-level overview of overall service health. Which two visualization types are most suitable for this purpose? (Select TWO).

    Show answer & explanation

    Correct answers: A, C

    The Service Health Score visualization is specifically designed for this purpose. It displays a service's health score as a colored shape (e.g., a hexagon or square), which is a common and effective way to represent overall status in a high-level monitoring view.

    The Single Value visualization is excellent for NOC dashboards as it clearly displays the current health score or value of a critical KPI. Its color changes based on severity, providing an immediate visual cue of status (e.g., green, yellow, red).

  5. Question 5Intermediate

    Entities and Modules · Importing entities

    An administrator is importing entities from a CSV file. The file contains columns for hostname, ip_address, and role. The administrator wants to use hostname as the primary identifier for the entity but also wants to be able to filter by role. How should the role column be configured during the import process?

    Show answer & explanation

    Correct answer: C

    Configuring the role column as an entity alias is the correct approach. The entity title (hostname) is the primary identifier. An alias provides an additional, searchable key-value pair associated with the entity. This allows KPI searches to be filtered or split by the alias role (e.g., role=webserver).

  6. Question 6Beginner

    Templates and Dependencies · Define dependencies between services

    What is the primary purpose of defining service dependencies in ITSI?

    Show answer & explanation

    Correct answer: A

    The primary purpose of service dependencies is to model the relationships between services so that the health status of a foundational (downstream) service can propagate to and impact the health of a service that relies on it (upstream). This enables more accurate root cause analysis and impact assessment.

  7. Question 7Intermediate

    KPI Configuration · Create KPIs with static and adaptive thresholds

    An ITSI admin needs to create a KPI that calculates the average response time for a web application. The logs contain a field named response_time_ms. The KPI should be calculated every 5 minutes and display the average value over that period. What is the correct value for the 'Search & Calculation' field in the KPI configuration?

    Show answer & explanation

    Correct answer: A

    In the KPI configuration, ITSI runs a base search first. The 'Search & Calculation' field expects only the statistical function to be applied to the results of the base search. Therefore, avg(response_time_ms) is the correct syntax. ITSI will automatically handle grouping the results over the 5-minute interval.

  8. Question 8Advanced

    Implementing Services · Use a service design to implement services in ITSI

    A manufacturing company uses ITSI to monitor its assembly line robotics. The health of the 'Robotics' service depends on three underlying services: 'Network Connectivity', 'Power Supply', and 'Control Software'. A failure in any of these three services is critical and should immediately set the 'Robotics' service health to critical. How should the health score calculation be configured for the 'Robotics' service?

    Show answer & explanation

    Correct answer: B

    This is the correct approach. By setting the 'Robotics' service to inherit the health score of its most critical dependency, a critical status in 'Power Supply', 'Network Connectivity', or 'Control Software' will immediately cause the parent 'Robotics' service to also become critical. This accurately reflects the business impact where any single failure is catastrophic.

  9. Question 9Intermediate

    Data Audit and Base Searches · Use a data audit to identify service key performance indicators

    An ITSI consultant is conducting a data audit for a new ITSI implementation at a retail company. The goal is to identify potential KPIs for an 'Online Store' service. The consultant has access to web server logs, application logs, and database logs. Which of the following is NOT a primary objective of the data audit phase?

    Show answer & explanation

    Correct answer: D

    The data audit phase focuses on discovering and validating data sources to determine what can be monitored. Building the final, production-ready glass tables is a later step in the implementation process that occurs after services and KPIs have been designed and created. While the audit might inform the design of glass tables, building them is not a primary objective of the audit itself.

  10. Question 10Intermediate

    Data Audit and Base Searches · Design base searches

    True or False: A base search in ITSI must be a transforming search that uses commands like stats, chart, or timechart.

    Show answer & explanation

    Correct answer: B

    This statement is false. A base search is simply the initial SPL query that gathers the raw data for one or more KPIs. The statistical calculations (like stats avg(field)) are typically defined in the individual KPI's 'Search & Calculation' field, not in the base search itself. The base search can be a simple, non-transforming search.

Ready for the real thing?

The full SPLK-3002 simulator has every exam-style question, timed mode, and instant scoring.