exam questions

Exam SPLK-1003 All Questions

View all questions & answers for the SPLK-1003 exam

Exam SPLK-1003 topic 1 question 83 discussion

Actual exam question from Splunk's SPLK-1003
Question #: 83
Topic #: 1
[All SPLK-1003 Questions]

An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data is 300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the index?

  • A. Buy a bigger Splunk license.
  • B. Add 2.5 TB each day for the next 5 days.
  • C. Add all 10 TB in a single 24 hour period.
  • D. Add 200 GB of historical data each day for 50 days.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jakal12345
Highly Voted 2 years, 11 months ago
D . 300GB is already coming in daily... now you can add only 200GB more each day... this way you'll have to split the 10TB historical data over 50 days ... and this'll solve the problem 300GB + 200GB Historical day = 500GB - which is under the license violation
upvoted 6 times
...
tinzs
Highly Voted 2 years, 1 month ago
Selected Answer: C
getting one warning is better than risking 50 times getting warnings and end up with a violation
upvoted 5 times
mpmp22
5 months, 3 weeks ago
Disagree. It says 24h period but the License warning is based on the incoming Data until the day ends/Midnight. So if you end up putting in 10TB over 24h you might risk getting two violations. In an example like this where there arent any other variables that could mess up the 300/200 Split, D is the correct answer to minimize. In a real World example it may look different though..
upvoted 1 times
...
...
NastyNutsu
Most Recent 6 days, 11 hours ago
Selected Answer: D
Even though it's a one-time ingestion (C), Splunk's license policies still apply. Adding 10 TB in a single 24-hour period would trigger a significant license violation, as it exceeds your 500 GB daily limit by a wide margin. Splunk doesn't differentiate between one-time and recurring data ingestion when it comes to licensing. So, do the right thing and go with (D).
upvoted 1 times
...
Kevin2015
3 weeks, 5 days ago
Selected Answer: C
The spunk admins has more than 100gb of license which doesn't current violate. Visit Splunk documentation on licensing for more
upvoted 1 times
...
Frank_Rai
3 months, 2 weeks ago
D. The best way to add 10 TB of historical data to the index without violating the daily license volume is option D: Add 200 GB of historical data each day for 50 days. Here's why each option stands as it does: A. Buying a bigger Splunk license would indeed solve the problem, but it's not the most cost-effective solution if you only need to index the historical data once. B. Adding 2.5 TB each day for the next 5 days would exceed the daily license volume of 500 GB, likely causing a license violation. C. Adding all 10 TB in a single 24-hour period would far exceed the daily volume allowed by the license, leading to a significant license violation. D. Adding 200 GB of historical data each day for 50 days would keep the total daily volume (new data + historical data) at 500 GB, avoiding any license violations. This approach utilizes the full capacity of the license without exceeding it, allowing the historical data to be indexed systematically over time without incurring additional costs or license issues.
upvoted 1 times
...
adamsca
1 year ago
Selected Answer: D
I vote D it makes more sense and would minimize any license issues.
upvoted 2 times
...
mngesha
1 year, 5 months ago
from the discussion on the following link it seems D is the better option maybe not the right but the better. https://docs.splunk.com/Documentation/Splunk/8.1.2/Admin/Aboutlicenseviolations
upvoted 2 times
...
Rolonar
1 year, 10 months ago
minimize- reduce (something, especially something unwanted or unpleasant) to the smallest possible amount or degree. Answer has to be D as it will allow you to ingest all the data with the least amount of license issues within the givne parameters. Also there is no way splunk is going to suggest that the best way to ingest large amounts of data is to violate their license agreement.
upvoted 3 times
...
BlueRoselia
2 years, 4 months ago
Answer D Do NOT ever go over your license quota violations are pricy; IT IS NOT BEST PRACTICE If we are only indexing 10TB of data once; no need for a license increase because it cost more money data will be a one shot upload
upvoted 2 times
...
Salman23
2 years, 10 months ago
C looks good to me. Adding the 10TB historical data within 24hours. Exeeding Indexing daily quota onece will trigger 1 alert then a warning but just when hitting 5 warnings in a 30 days will trigger a violation.
upvoted 1 times
...
jm130106
2 years, 11 months ago
https://docs.splunk.com/Documentation/Splunk/8.1.2/Admin/Aboutlicenseviolations "An Enterprise license stack with a license volume of 100 GB of data per day or more does not currently violate." Then the answer is C Add all 10 TB in a single 24 hour period given the 500GB license will not have a violation.
upvoted 2 times
...
Hudda
3 years ago
Friends, could you please confirm this answer C or D?
upvoted 1 times
...
mybox1
3 years, 6 months ago
C sounds better, it's one time shot. Adding 200GB data during next 50 days doesn't minimize issue since it causes 50 chances of license warnings (5 warnings causes violation)
upvoted 3 times
hwangho
3 years, 6 months ago
it does minimize license issue. we are not talking about data migration issue here. we are talking about license issue. if you are getting alert or warning, or violation....those are the license issue.
upvoted 2 times
...
...
hwangho
3 years, 6 months ago
Answer is D, since the question is asking "To minimize license issues, what is the best way to add 10 TB of historical data to the index?"....I think the key word is "minimize".
upvoted 4 times
ucsdmiami2020
2 years, 10 months ago
Per the provided Reference URL https://docs.splunk.com/Documentation/Splunk/8.1.2/Admin/Aboutlicenseviolations Scrolling down to the section titled, Avoiding license warnings, reads To avoid license warnings, monitor the license usage over time and ensure that you have sufficient license volume to support your daily license use: - Use the license usage report view on the license to troubleshoot index volume. - Enable an alert on the monitoring console to monitor daily license usage.
upvoted 1 times
...
AngusBlack
3 years ago
I agree. The question is not very "real world", but D would incur no license violations and therefore "minimize" license issues
upvoted 2 times
SasnycoN
2 years, 7 months ago
It says "To minimize license issues". Transferring 200GB every day when you are using 300GB daily means that even 1MB above that will trigger an alert. As the Splunk Documentations says: To avoid license warnings, monitor the license usage over time and ensure that you have sufficient license volume to support your daily license use
upvoted 2 times
...
...
mybox1
3 years, 6 months ago
I agree (that C) but it will be license warning, not violation.
upvoted 2 times
ucsdmiami2020
2 years, 10 months ago
Question does not explicitly say license warning or even violation, instead it states, "To minimize license issues"
upvoted 1 times
...
...
...
ugo1
3 years, 8 months ago
I think the Ans is C Adding the 10TB historical data within 24hours of license usage will trigger license violation only once.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago