Splunk Enterprise Security Certified Admin — Question 73

When using distributed configuration management to create the Splunk_TA_ForIndexers package, which three files can be included?

Answer options

Correct answer: A

Explanation

The correct answer is A because indexes.conf, props.conf, and transforms.conf are essential files for configuring Splunk indexers. Options B, C, and D contain files that may not be relevant to indexer configuration or are used for different purposes within Splunk.