Splunk Enterprise Certified Admin — Question 2

How can indexer acknowledgement be enabled for HTTP Event Collector (HEC)? (Select all that apply.)

Answer options

Correct answer: C, D

Explanation

The correct answers, C and D, involve directly enabling indexer acknowledgement through the Splunk Web interface during token creation or Global Settings updates. Option A is incorrect because indexer acknowledgement is not enabled by default, and option B is misleading as it does not apply to the HEC token creation process in that manner.