Splunk Enterprise Security Certified Admin — Question 60
Which tool is used to update indexers in ES?
Answer options
- A. Distributed Configuration Management
- B. Index Updater
- C. indexes.conf
- D. Splunk_TA_ForIndexers.spl
Correct answer: D
Explanation
The correct answer is D, Splunk_TA_ForIndexers.spl, which specifically provides the necessary configurations and updates for indexers within the Enterprise Security (ES) framework. Options A, B, and C do not directly pertain to the process of updating indexers; instead, they refer to broader management concepts or specific configuration files that do not serve the same purpose.