Splunk Enterprise Certified Architect — Question 27

A customer has scoped their environment:

• Data ingest of 600 GB / day
• 1 standalone search head
• 3 clustered indexers

They have purchased an ingest license for 900 GB / day. What is the simplest way to configure their license using Splunk best practices?

Answer options

Correct answer: D

Explanation

The correct answer is D because using the default pool size of 900 GB simplifies management and aligns with best practices, as the client's daily ingest is well within the allowed limit. The other options complicate the configuration unnecessarily and do not take full advantage of the available license capacity.