Splunk Core Certified Advanced Power User — Question 100
An index stores its data in buckets. Which default directories does Splunk use to store buckets? (Choose all that apply.)
Answer options
- A. bucketdb
- B. frozendb
- C. colddb
- D. db
Correct answer: C, D
Explanation
The correct answers are C and D because Splunk uses 'coldb' for cold buckets and 'db' for hot and warm buckets. Options A and B, 'bucketdb' and 'frozendb', are not standard directories used by Splunk for bucket storage.