
SplunkEnterprise Certified Architect
Domain 5Objective 3
Tune Props.conf SPLK-2002 Practice Questions (Page 3)
Part of the Performance Monitoring and Tuning domain, which makes up ~9% of our current practice bank. Splunk does not publish an official question count, but from its 90-minute exam (~35–60 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
7concepts
Questions 11–15
- 11
What is the purpose of the SEGMENTATION setting in props.conf?
Select an answer first - 12
An admin has tuned props.conf for a custom sourcetype and deployed the changes to a heavy forwarder. After deployment, they notice that events are being indexed with incorrect timestamps. The admin wants to verify whether the issue is with the props.conf configuration or something else. Which step should they take first?
Select an answer first - 13
Which props.conf setting limits the maximum number of bytes that Splunk reads for a single event?
Select an answer first - 14
What is the purpose of the MAX_TIMESTAMP_LOOKAHEAD setting in props.conf?
Select an answer first - 15
An admin is tuning event breaking for a sourcetype that has very large events (up to 1 MB). The default LINE_BREAKER is causing the indexer to consume excessive memory and CPU. The team wants to reduce resource usage while maintaining correct event boundaries. What should they consider?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-2002” is a trademark of its owner, used for identification only.