Splunk IT Service Intelligence Certified Admin Exam Questions and Answers
Question 17
Which of the following can generate notable events?
Options:
A.
Through ad-hoc search results which get processed by adaptive thresholds.
B.
When two entity aliases have a matching value.
C.
Through scheduled correlation searches which link to their respective services.
D.
Manually selected using the Notable Event Review panel.
Answer:
C
Explanation:
Explanation:
Notable events in Splunk IT Service Intelligence (ITSI) are primarily generated through scheduled correlation searches. These searches are designed to monitor data for specific conditions or patterns defined by the ITSI administrator, and when these conditions are met, a notable event is created. These correlation searches are often linked to specific services or groups of services, allowing for targeted monitoring and alerting based on the operational needs of those services. This mechanism enables ITSI to provide timely and relevant alerts that can be further investigated and managed through the Episode Review dashboard, facilitating efficient incident response and management within the IT environment.
Question 18
Which of the following accurately describes base searches used for KPIs in a service?
Options:
A.
Base searches can be used for multiple services.
B.
A base search can only be used by its service and all dependent services.
C.
All the metrics in a base search are used by one service.
D.
All the KPIs in a service use the same base search.
Answer:
A
Explanation:
Explanation:
KPI base searches let you share a search definition across multiple KPIs in IT Service Intelligence (ITSI). Create base searches to consolidate multiple similar KPIs, reduce search load, and improve search performance.
Reference: [Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/BaseSearch, A base search is a search definition that can be shared across multiple KPIs that use the same data source. Base searches can improve search performance and reduce search load by consolidating multiple similar KPIs. The statement that accurately describes base searches used for KPIs in a service is:, A. Base searches can be used for multiple services. This means that you can create a base search for a service and use it for other services that have similar data sources and KPIs. For example, if you have multiple services that monitor web server performance, you can create a base search that queries the web server logs and use it for all the services that need to calculate KPIs based on those logs., , , ]
Question 19
Which of the following is a characteristic of base searches?
Options:
A.
Search expression, entity splitting rules, and thresholds are configured at the base search level.
B.
It is possible to filter to entities assigned to the service for calculating the metrics for the service’s KPIs.
C.
The fewer KPIs that share a common base search, the more efficiency a base search provides, and anomaly detection is more efficient.
D.
The base search will execute whether or not a KPI needs it.
Answer:
B
Explanation:
Reference: [Reference: https://docs.splunk.com/Documentation/ITSI/4.10.2/SI/BaseSearch, A base search is a search definition that can be shared across multiple KPIs that use the same data source. Base searches can improve search performance and reduce search load by consolidating multiple similar KPIs. One of the characteristics of base searches is that it is possible to filter to entities assigned to the service for calculating the metrics for the service’s KPIs. This means that you can use entity filtering rules to specify which entities are relevant for each KPI based on the base search results. References: Create KPI base searches in ITSI, [Filter entities for KPIs based on base searches]]
Question 20
Which capabilities are enabled through “teams”?
Options:
A.
Teams allow searches against the itsi_summary index.
B.
Teams restrict notable event alert actions.
C.
Teams restrict searches against the itsi_notable_audit index.
D.
Teams allow restrictions to service content in UI views.
Answer:
D
Explanation:
Explanation:
D is the correct answer because teams allow you to restrict access to service content in UI views such as service analyzers, glass tables, deep dives, and episode review. Teams alsocontrol access to services and KPIs for editing and viewing purposes. Teams do not affect the ability to search against the itsi_summary index, restrict notable event alert actions, or restrict searches against the itsi_notable_audit index. References: Overview of teams in ITSI