Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

SPLK-3002 Exam Questions & Answers

Splunk IT Service Intelligence Certified Admin  •  Splunk

96 Questions 60 min Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample SPLK-3002 Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

Which of the following items apply to anomaly detection? (Choose all that apply.)

Correct Answer: B, C
Explanation:

Anomaly detection is a feature of ITSI that uses machine learning to detect when KPI data deviates from a normal pattern. The following items apply to anomaly detection:

B . A minimum of 24 hours of data is needed for anomaly detection, and a minimum of 4 entities for cohesive analysis. This ensures that there is enough data to establish a baseline pattern and compare different entities within a service.

C . Anomaly detection automatically generates notable events when KPI data diverges from the pattern. You can configure the sensitivity and severity of the anomaly detection alerts and assign them to episodes or teams. Reference: [Anomaly Detection]

Q2 MultipleChoice

Which of the following are the default ports that must be configured on Splunk to use ITSI?

Correct Answer: C
Explanation:

C is the correct answer because ITSI uses the default ports of Splunk Enterprise for its communication and data collection. SplunkWeb uses port 8000, SplunkD uses port 8089, and HTTP Event Collector uses port 8088. These ports can be changed if needed, but they must match the configuration of Splunk Enterprise. Reference:Ports used by ITSI

Q3 MultipleChoice

What are valid ITSI Glass Table editor capabilities? (Choose all that apply.)

Correct Answer: A, C, D
Explanation:

Create a glass table to visualize and monitor the interrelationships and dependencies across your IT and business services.

The service swapping settings are saved and apply the next time you open the glass table.

You can add metrics like KPIs, ad hoc searches, and service health scores that update in real time against a background that you design. Glass tables show real-time data generated by KPIs and services.


The glass table editor is a tool that allows you to create and edit glass tables in ITSI. Some of the capabilities of the glass table editor are:

Creating glass tables from scratch or from existing templates.

Configuring service swapping on widgets to toggle displaying metrics from different services.

Adding KPI metric lanes to glass tables to show historical trends of KPI values.

The glass table editor does not support correlation search creation, which is a separate feature in ITSI that allows you to create searches that look for relationships between data points and generate notable events. Reference:Overview of the glass table editor in ITSI, [Configure service swapping on glass tables], [Add KPI metric lanes to glass tables], [Overview of correlation searches in ITSI]

Q4 MultipleChoice

When creating a custom deep dive, what color are services/KPIs in maintenance mode within the topology view?

Correct Answer: A
Explanation:

When creating a custom deep dive, services or KPIs that are in maintenance mode are shown in gray color in the topology view. This indicates that they are not actively monitored and do not generate alerts or notable events. Reference:Deep Dives

Q5 MultipleChoice

Which of the following best describes an ITSI Glass Table?

Correct Answer: A
Explanation:

An ITSI Glass Table provides a customizable, high-level view that can display a system's topology overlaid with real-time Key Performance Indicator (KPI) metrics and service health scores. This visualization tool allows users to create a visual representation of their IT infrastructure, applications, and services, integrating live data to monitor the health and performance of each component in context. The ability to overlay KPI metrics on the system topology enables IT and business stakeholders to quickly understand the operational status and health of various elements within their environment, facilitating more informed decision-making and rapid response to issues.

Get access to all 96 verified questions with detailed answers.

Unlock All SPLK-3002 Questions

Frequently Asked Questions

Candidates should have a solid understanding of Splunk fundamentals and practical experience with Splunk IT Service Intelligence (ITSI). Splunk recommends having at least 6-12 months of hands-on experience with ITSI before attempting the certification exam.

The SPLK-3002 exam consists of multiple-choice questions and typically lasts 90 minutes. Candidates must achieve a passing score of 70% or higher to earn the certification.

The exam covers ITSI architecture, configuration, glass tables, correlation searches, entity management, KPI calculations, and dashboarding. It also includes content management, deployment considerations, and best practices for implementing ITSI solutions.

Splunk offers official training courses, documentation, and study guides for ITSI certification. Hands-on practice in a Splunk environment, reviewing the exam objectives, and utilizing practice exams are recommended preparation strategies.

Splunk certifications typically need to be renewed periodically to ensure professionals maintain current knowledge. Check Splunk's official certification website for specific recertification requirements and validity periods for the SPLK-3002 credential.
Exam Details
  • Exam CodeSPLK-3002
  • VendorSplunk
  • Total Questions96
  • Duration60 min
  • LanguageEnglish
  • Last UpdatedSep 1, 2026
4.9/5

Pass SPLK-3002 First Time

Get all 96 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals