Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkEnterprise Certified Architect

Domain 5Objective 3

Tune Props.conf SPLK-2002 Practice Questions (Page 2)

Part of the Performance Monitoring and Tuning domain, which makes up ~9% of our current practice bank. Splunk does not publish an official question count, but from its 90-minute exam (~35–60 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
7concepts

Questions 6–10

  1. 6application · medium

    A team ingests logs where the timestamp is not at the beginning but appears after a variable-length prefix, such as 'host=web01 [2024-05-01 12:00:00] message'. The default timestamp extraction is slow because Splunk searches the entire event. They want to optimize timestamp extraction. Which setting should they configure?

    Select an answer first
  2. 7foundation · easy

    What does the INDEX_EXTRACTIONS setting control in props.conf?

    Select an answer first
  3. 8expert · hard

    An admin has made several props.conf changes to improve performance, including changes to LINE_BREAKER, TIME_PREFIX, and SEGMENTATION. After deploying to a test indexer, they notice that some events are missing or have incorrect timestamps. They want to identify which change is causing the issue without affecting production. What is the best approach?

    Select an answer first
  4. 9foundation · easy

    What is the function of the BREAK_ONLY_BEFORE setting in props.conf?

    Select an answer first
  5. 10expert · hard

    A company ingests logs from multiple sources where the timestamp format varies. Some logs have timestamps in the format '2024-05-01 12:00:00', others have 'May 1 12:00:00', and some have epoch timestamps. The team wants to optimize timestamp extraction for all formats without sacrificing performance. What is the best approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-2002” is a trademark of its owner, used for identification only.