Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkEnterprise Certified Architect

Domain 5Objective 3

Tune Props.conf SPLK-2002 Practice Questions (Page 1)

Part of the Performance Monitoring and Tuning domain, which makes up ~9% of our current practice bank. Splunk does not publish an official question count, but from its 90-minute exam (~35–60 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
7concepts

Questions 1–5

  1. 1foundation · easy

    Which props.conf setting is used to reference a transformation defined in transforms.conf?

    Select an answer first
  2. 2expert · hard

    A team ingests a mix of structured and unstructured logs. The structured logs are frequently searched by field, while the unstructured logs are only searched by time. The current configuration uses the same props.conf settings for both, causing slow search performance on structured logs and unnecessary indexing overhead on unstructured logs. What is the best approach?

    Select an answer first
  3. 3foundation · easy

    How can transforms.conf be used in conjunction with props.conf to improve indexing performance?

    Select an answer first
  4. 4foundation · easy

    Which props.conf setting uses a regular expression to define how raw data is split into events?

    Select an answer first
  5. 5application · medium

    A company ingests large volumes of raw network flow logs that are rarely searched by field. The logs are stored for compliance and only need to be searchable by time range. The indexing pipeline is struggling to keep up with the volume, and the team wants to improve indexing throughput without significantly affecting search performance for their use case. Which props.conf setting should be adjusted?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-2002” is a trademark of its owner, used for identification only.