Splunk Enterprise Certified Architect — Question 67

As of Splunk 9.0, which index records changes to .conf files?

Answer options

Correct answer: C

Explanation

The correct answer is C, _configtracker, as it specifically tracks changes to configuration files, including .conf files. The other options, such as _audit and _internal, serve different purposes, such as logging user activity and internal system events, respectively, while _introspection is related to performance monitoring.