Splunk Enterprise Certified Architect — Question 67
As of Splunk 9.0, which index records changes to .conf files?
Answer options
- A. _audit
- B. _internal
- C. _configtracker
- D. _introspection
Correct answer: C
Explanation
The correct answer is C, _configtracker, as it specifically tracks changes to configuration files, including .conf files. The other options, such as _audit and _internal, serve different purposes, such as logging user activity and internal system events, respectively, while _introspection is related to performance monitoring.