exam questions

Exam SPLK-2002 All Questions

View all questions & answers for the SPLK-2002 exam

Exam SPLK-2002 topic 1 question 1 discussion

Actual exam question from Splunk's SPLK-2002
Question #: 1
Topic #: 1
[All SPLK-2002 Questions]

Which of the following will cause the greatest reduction in disk size requirements for a cluster of N indexers running Splunk Enterprise Security?

  • A. Setting the cluster search factor to N-1.
  • B. Increasing the number of buckets per index.
  • C. Decreasing the data model acceleration range.
  • D. Setting the cluster replication factor to N-1.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Crash_Override
Highly Voted 3 years, 1 month ago
Selected Answer: A
Replicated copies of non-searchable data are smaller than copies of searchable data, because they include only the data and not the associated index files. So setting search factor to n-1 has a greater reduction.
upvoted 12 times
...
62d8e4c
Most Recent 8 months ago
Selected Answer: D
If you only have one copy (RF = 1) by default your SF is 1, so the right answer is D.
upvoted 1 times
...
bobixaka
1 year, 2 months ago
Selected Answer: A
TSIDX files are bigger than the raw data, so A is the correct answer. If you reduce the number of searchable data copies you will have a greater impact on storage savings. We are assuming that the current search_factor=N and replication_factor=N.
upvoted 1 times
...
FreshLearn
1 year, 3 months ago
IMHO the question is tricky and has a massive 'it depends' in it, but considering N could be any cluster size, let's assume we have a requirement of 2 searchable copies and a replication factor of 4(=4x raw data distributed accross the nodes total) and a cluster with 50 peer nodes => so you set it with A) to 49(!) full sized searchable copies D) to 49(!) smaller sized raw copies in contrast "C) Decreasing the data model acceleration range." would actually DECREASE consumed storage
upvoted 1 times
...
_bert
1 year, 8 months ago
Replication factor (RF) is the number of copies of a bucket. Search factor (SF) is the number of those copies which are searchable. You can't search more copies than you have so SF must be less than or equal to RF. By reducing RF to N-1 you are automatically reducing the SF to N-1. So answer is D.
upvoted 2 times
...
Sledge_Hammer
1 year, 11 months ago
D is the right answer. Replication factor is RECOMMENDED to be set at 1 less than the number of peer nodes (N-1)
upvoted 1 times
Harllen91
1 year, 10 months ago
Architecting Splunk Enterprise Deployments, "Best Practice: Minimum (RF +1) peer nodes. You have a replication factor of 3, then you want 4 peer nodes, not one less.
upvoted 1 times
...
...
stwong
2 years, 5 months ago
Seems the question assumes SF is always smaller than RF, while RF in example in https://docs.splunk.com/Documentation/Splunk/7.3.2/Indexer/Systemrequirements equal to cluster size, e.g. 3 peer nodes, with replication factor = 3; search factor = 2 5 peer nodes, with replication factor = 5; search factor = 3 In these cases, setting SF=N-1 will increase disk usage instead, while since RF=N in both cases, setting RF=N-1 will reduce disk usage. Is that why having answer = D ?
upvoted 3 times
...
javo_dlg
2 years, 7 months ago
Answer A is correct
upvoted 2 times
...
SplunkStreamer
2 years, 8 months ago
Selected Answer: A
Answer: A
upvoted 1 times
...
frappe
2 years, 9 months ago
Selected Answer: A
Answer A seems correct as Replicated copies of non-searchable data are smaller than copies of searchable data, because they include only the data and not the associated index files.
upvoted 1 times
...
RedYeti
2 years, 12 months ago
Selected Answer: A
Answer A
upvoted 2 times
...
manu78
4 years, 1 month ago
A is the correct Answer
upvoted 1 times
...
sunil299
4 years, 2 months ago
Answer A seems correct as Replicated copies of non-searchable data are smaller than copies of searchable data, because they include only the data and not the associated index files.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago