SPLK-3002 Splunk IT Service Intelligence Certified Admin Exam

Track Overview
A Splunk IT Service Intelligence Certified Admin installs and configures Splunk’s app for IT Service Intelligence (ITSI), including ITSI architecture, deployment planning, service design and implementation, notable events, and developing glass tables and deep dives. This certification demonstrates an individual’s ability to deploy, manage, and utilize Splunk ITSI to monitor mission-critical services.

Prerequisite Certification(s): None
Prerequisite Course(s): None

Candidates who wish to prepare for the Splunk IT Service Intelligence Certified Admin exam are recommended to complete the following course:
Implementing Splunk IT Service Intelligence

Candidates for the Splunk IT Service Intelligence Certified Admin exam are also expected to having working knowledge and experience as either Splunk Cloud or Splunk Enterprise Administrators.

Certification Exam
Candidates who have completed all of the above requirements may register for the Certification exam via testing partner Pearson VUE. Those who need step-by-step registration assistance should refer to our Exam Registration Tutorial.

The Splunk Certification Exams Study Guide contains important details regarding exam preparation and delivery.

Good luck!

Course Topics
ITSI architecture and deployment
Installing ITSI
Designing Services-discovery and best practices
Implementing services and entities
Configuring correlation searches and multi KPI alerts
Managing aggregation policies and anomaly detection
Troubleshooting and maintenance

Course Prerequisites
Splunk Fundamentals 1
Splunk Fundamentals 2
Splunk Enterprise System Administration
Splunk Enterprise Data Administration

Course Objectives

Module 1 – Introducing ITSI

Identify what ITSI does
Describe reasons for using ITSI
Examine the ITSI user interface

Module 2 – Glass Tables
Describe glass tables
Use glass tables
Design glass tables
Configure glass tables

Module 3 – Managing Notable Events
Define key notable events terms and their relationships
Describe examples of multi-KPI alerts
Describe the notable events workflow
Work with notable events

Module 4 – Investigating Issues with Deep Dives
Describe deep dive concepts and their relationships
Use default deep dives
Create and customize new custom deep dives
Add and configure swim lanes
Custom views
Describe effective workflows for troubleshooting

Module 5 – Installing and Configuring ITSI
List ITSI hardware recommendations
Describe ITSI deployment options
Identify ITSI components
Describe the installation procedure
Identify data input options for ITSI
Add custom data to an ITSI deployment

Module 6 – Designing Services
Given customer requirements, plan an ITSI implementation
Identify site entities

Module 7 – Data Audit and Base Searches
Use a data audit to identify service key performance indicators
Design base searches

Module 8 – Implementing Services
Use a service design to implement services in ITSI

Module 9 – Thresholds and Time Policies
Create KPIs with static and adaptive thresholds
Use time policies to define flexible thresholds

Module 10 – Entities and Dependencies
Using entities in KPI searches
Defining dependencies

Module 11 – Correlation and Multi KPI Searches
Define new correlation searches
Define multi KPI alerts
Manage notable event storage

Module 12 – Aggregation Policies
Create new aggregation policies
Use smart mode

Module 13 – Anomaly Detection
Enable anomaly detection
Work with generated anomaly events

Module 14 – Access Control
Configure user access control
Create service level teams

Module 15 – Troubleshooting ITSI
Backup and restore
Maintenance mode
Creating modules
Troubleshooting

QUESTION 1
After a notable event has been closed, how long will the meta data for that event remain in the KV Store by default?

A. 6 months.
B. 9 months.
C. 1 year.
D. 3 months.

Answer: A

QUESTION 2
Which of the following is a best practice for identifying the most effective services with which to start an iterative ITSI deployment?

A. Only include KPIs if they will be used in multiple services.
B. Analyze the business to determine the most critical services.
C. Focus on low-level services.
D. Define a large number of key services early.

Answer: A

QUESTION 3
When creating a custom deep dive, what color are services/KPIs in maintenance mode within the topology view?

A. Gray
B. Purple
C. Gear Icon
D. Blue

Answer: A

Examkingdom Splunk SPLK-3002 Exam pdf, Certkingdom Splunk SPLK-3002 PDF

MCTS Training, MCITP Trainnig

Best Splunk SPLK-3002 Certification, Splunk SPLK-3002 Training at certkingdom.com

SPLK-3002 Splunk IT Service Intelligence Certified Admin Exam
Scroll to top