Exam Code: SPLK-2002
Exam Questions: 208
Splunk Enterprise Certified Architect
Updated: 02 Sep, 2026
Viewing Page : 1 - 21
Practicing : 1 - 5 of 208 Questions
Question 1

A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)

Options :
Answer: D

Question 2

When using the props.conf LINE_BREAKER attribute to delimit multi-line events, the
SHOULD_LINEMERGE attribute should be set to what?

Options :
Answer: C

Question 3

Consider a use case involving firewall data. There is no Splunk-supported Technical Add-On, but the vendor
has built one. What are the items that must be evaluated before installing the add-on? (Select all that apply.)

Options :
Answer: A,C

Question 4

Which Splunk Enterprise offering has its own license?

Options :
Answer: C

Question 5

What is the expected minimum amount of storage required for data across an indexer cluster with the

following input and parameters?

• Raw data = 15 GB per day

• Index files = 35 GB per day

• Replication Factor (RF) = 2

• Search Factor (SF) = 2

Options :
Answer: C

Viewing Page : 1 - 21
Practicing : 1 - 5 of 208 Questions

© Copyrights FreePDFQuestions 2026. All Rights Reserved

We use cookies to ensure that we give you the best experience on our website (FreePDFQuestions). If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the FreePDFQuestions.