New Year Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dm70dm

SPLK-3002 Splunk IT Service Intelligence Certified Admin Exam Questions and Answers

Questions 4

What is the default importance value for dependent services’ health scores?

Options:

A.

11

B.

1

C.

Unassigned

D.

10

Buy Now
Questions 5

What is the minimum number of entities a KPI must be split by in order to use Entity Cohesion anomaly detection?

Options:

A.

3

B.

4

C.

5

D.

2

Buy Now
Questions 6

Which of the following best describes a default deep dive?

Options:

A.

It initially shows the health scores for all services.

B.

It initially shows the highest importance KPIs.

C.

It initially shows all of the KPIs for a selected service.

D.

It initially shows all the entity swim lanes.

Buy Now
Questions 7

Which glass table feature can be used to toggle displaying KPI values from more than one service on a single widget?

Options:

A.

Service templates.

B.

Service dependencies.

C.

Ad-hoc search.

D.

Service swapping.

Buy Now
Questions 8

Which of the following items describe ITSI teams? (select all that apply)

Options:

A.

Teams should have itoa admin roles added with read-only permissions for services and entities.

B.

Services should be assigned to the 'global' team if all users need access to it.

C.

By default, all services are owned by the built-in 'global' team and administered by the 'itoa_admin' role.

D.

A new team admin role should be created for each team. The new role should inherit the 'itoa_team_admin' role.

Buy Now
Questions 9

What is the range for a normal Service Health score category?

Options:

A.

20-40

B.

40-60

C.

60-80

D.

80-100

Buy Now
Questions 10

Within a correlation search, dynamic field values can be specified with what syntax?

Options:

A.

fieldname

B.

C.

%fieldname%

D.

eval(fieldname)

Buy Now
Questions 11

What happens when an anomaly is detected?

Options:

A.

A separate correlation search needs to be created in order to see it.

B.

A SNMP trap will be sent.

C.

An anomaly alert will appear in core splunk, in index=main.

D.

An anomaly alert will appear as a notable event in Episode Review.

Buy Now
Questions 12

What is the main purpose of the service analyzer?

Options:

A.

Display a list of All Services and Entities.

B.

Trigger external alerts based on threshold violations.

C.

Allow Analysts to add comments to Alerts.

D.

Monitor overall Service and KPI status.

Buy Now
Questions 13

What is an episode?

Options:

A.

A workflow task.

B.

A deep dive.

C.

A notable event group.

D.

A notable event.

Buy Now
Questions 14

Which of the following describes enabling smart mode for an aggregation policy?

Options:

A.

Configure –> Policies –> Smart Mode –> Enable, select “fields”, click “Save”

B.

Enable grouping in Notable Event Review, select “Smart Mode”, select “fields”, and click “Save”

C.

Edit the aggregation policy, enable smart mode, select fields to analyze, click “Save”

D.

Edit the notable event view, enable smart mode, select “fields”, and click “Save”

Buy Now
Questions 15

Which anomaly detection algorithm fulfills the paired monitoring requirement?

Options:

A.

Detection algorithm: Trending anomaly detection

Monitoring requirement: Produce an alert when an entity deviates from its historical behavior.

B.

Detection algorithm: Entity cohesion anomaly detection

Monitoring requirement: Produce an alert when one entity in the KPI is not behaving similar to other entities in the KPI.

C.

Detection algorithm: Trending anomaly detection

Monitoring requirement: Produce an alert when one entity in the KPI is not behaving similar to other entities in the KPI.

D.

Detection algorithm: Entity cohesion anomaly detection

Monitoring requirement: Produce an alert when multiple KPIs in the service deviate from their historical behaviors.

Buy Now
Questions 16

Which of the following are characteristics of service templates? (select all that apply)

Options:

A.

Service templates can be modified after services are instantiated from it.

B.

Service templates contain KPIs and KPI thresholds.

C.

Service templates can contain specific or generic entity rules.

D.

Service templates contain domain specific dashboards and deep dives.

Buy Now
Questions 17

When installing ITSI to support a Distributed Search Architecture, which of the following items apply? (Choose all that apply.)

Options:

A.

Copy SA-IndexCreation to all indexers.

B.

Copy SA-IndexCreation to the etc/apps directory on the index cluster master node.

C.

Extract installer package into etc/apps directory of the cluster deployer node.

D.

Extract ITSI app package into etc/apps directory of search head.

Buy Now
Questions 18

How can Service Now incidents be created automatically when a Multi-KPI alert triggers? (select all that apply)

Options:

A.

By creating a custom etc/apps/SA-lTOA/workflow_rules. conf

B.

By linking Entities to Service-Now configuration items.

C.

By creating a notable event aggregation policy with a SNOW incident action.

D.

By editing the associated correlation search and specifying an alert action.

Buy Now
Questions 19

Which of the following is a characteristic of custom deep dives?

Options:

A.

Allows itoa_analyst roles to add comments.

B.

Requires at least 7 days' data to show anomalies.

C.

Combines metric, event, KPI, and service health score lanes.

D.

Uses drilldown to generate notable events via anomaly detection.

Buy Now
Questions 20

What are valid ITSI Glass Table editor capabilities? (Choose all that apply.)

Options:

A.

Creating glass tables.

B.

Correlation search creation.

C.

Service swapping configuration.

D.

Adding KPI metric lanes to glass tables.

Buy Now
Questions 21

Which of the following are the default ports that must be configured on Splunk to use ITSI?

Options:

A.

SplunkWeb (8405), SplunkD (8519), and HTTP Collector (8628)

B.

SplunkWeb (8089), SplunkD (8088), and HTTP Collector (8000)

C.

SplunkWeb (8000), SplunkD (8089), and HTTP Collector (8088)

D.

SplunkWeb (8088), SplunkD (8089), and HTTP Collector (8000)

Buy Now
Questions 22

How should entities be handled during the data audit phase of requirements gathering?

Options:

A.

Entity meta-data for info and aliases should be identified and recorded as requirements.

B.

Entities should be noted based upon Service KPI requirements such as 'by host' or 'by product line'.

C.

Entities must be identified for every Service KPI defined and recorded in requirements.

D.

Entities identified should be included in the entity filtering requirements, such as 'by processld' or 'by host'.

Buy Now
Questions 23

Which ITSI components are required before a module can be created?

Options:

A.

One or more entity import saved searches.

B.

One or more services with KPIs and their associated base searches.

C.

One or more datamodels.

D.

One or more correlation searches and their associated entities.

Buy Now
Questions 24

Which of the following actions can be performed with a deep dive?

Options:

A.

Create a Multi-KPI alert from the deep dive's current state to warn of similar situations in the future.

B.

Create a predictive analysis model from the deep dive to warn of future service degradation.

C.

Create an anomaly detection alert to show when the same pattern begins in the future.

D.

Create a custom service analyzer from selected deep dive lanes.

Buy Now
Questions 25

Which index will contain useful error messages when troubleshooting ITSI issues?

Options:

A.

_introspection

B.

_internal

C.

itsi_summary

D.

itsi_notable_audit

Buy Now
Questions 26

To use Adaptive Threshholding, what is the minimum requirement for a set of KPI data?

Options:

A.

14 days old.

B.

7 days old.

C.

30 days old.

D.

10 days old.

Buy Now
Questions 27

Which index contains ITSI Episodes?

Options:

A.

itsi_tracked_alerts

B.

itsi_grouped_alerts

C.

itsi_notable_archive

D.

itsi_summary

Buy Now
Questions 28

Which of the following describes a way to delete multiple duplicate entities in ITSI?

Options:

A.

Via c CSV upload.

B.

Via the entity lister page.

C.

Via a search using the | deleteentity command.

D.

All of the above.

Buy Now
Exam Code: SPLK-3002
Exam Name: Splunk IT Service Intelligence Certified Admin Exam
Last Update: Dec 24, 2025
Questions: 96

PDF + Testing Engine

$49.5  $164.99

Testing Engine

$37.5  $124.99
buy now SPLK-3002 testing engine

PDF (Q&A)

$31.5  $104.99
buy now SPLK-3002 pdf
dumpsmate guaranteed to pass

24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 24 Dec 2025