
SplunkCore Certified Consultant
Domain 4Objective 2
Articulate How One Splunk Instance Communicates with Another Splunk Instance (S2S) CORE-CERTIFIED-CONSULTANT Practice Questions (Page 2)
Part of the Data Collection domain, which accounts for 15% of the CORE-CERTIFIED-CONSULTANT exam. Splunk does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
6concepts
15%of the exam
Questions 6–10
- 6
Which Splunk command or tool is commonly used to verify that a forwarder is successfully sending data to an indexer?
Select an answer first - 7
A company has a Splunk deployment with a heavy forwarder that collects data from a legacy application and forwards it to a central indexer. The heavy forwarder also needs to send a copy of the same data to a second indexer in a different data center for disaster recovery. What is the most efficient way to configure this?
Select an answer first - 8
A Splunk admin has a forwarder sending data to an indexer with `useACK = true`. The admin notices that the forwarder's queue is consistently near capacity, and `ack_failures` in metrics.log is slowly increasing. The indexer is healthy and has plenty of resources. What is the most likely cause?
Select an answer first - 9
A Splunk admin needs to send data from a universal forwarder to an indexer. The indexer is listening on the default S2S port. The admin writes the following to outputs.conf: `[tcpout] defaultGroup = primary` and `[tcpout:primary] server = indexer.example.com:9997`. The forwarder restarts, but no data is sent. What is the most likely reason?
Select an answer first - 10
A Splunk admin is troubleshooting data loss. The forwarder's outputs.conf has `useACK = true`, but the admin notices that during a brief indexer outage, some events were never indexed. The forwarder's metrics.log shows `ack_failures` increasing. What is the most likely reason for the data loss?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CORE-CERTIFIED-CONSULTANT” is a trademark of its owner, used for identification only.