Exam SPLK-2002 All QuestionsBrowse all questions from this exam
Question 30

Splunk Enterprise platform instrumentation refers to data that the Splunk Enterprise deployment logs in the _introspection index. Which of the following logs are included in this index? (Select all that apply.)

    Correct Answer: C, D

    The introspection index in Splunk Enterprise logs data relevant to the platform's operation and performance. This includes various internal metrics and usage logs. Specifically, it includes logs like disk_objects.log, which tracks disk I/O operations, and resource_usage.log, which monitors the usage of different system resources. These logs are essential for troubleshooting and ensuring the Splunk Enterprise platform runs efficiently. Audit.log and metrics.log are not included in the introspection index.

Discussion
RedYetiOptions: CD

Answers C and D https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Abouttheplatforminstrumentationframework

BianchiOptions: CD

https://docs.splunk.com/Documentation/Splunk/8.2.5/Troubleshooting/Whatdatagetslogged CD

sutcocukOptions: CD

C&D https://docs.splunk.com/Documentation/Splunk/8.2.5/Troubleshooting/Whatdatagetslogged