Splunk Enterprise Security Certified Admin — Question 73
When using distributed configuration management to create the Splunk_TA_ForIndexers package, which three files can be included?
Answer options
- A. indexes.conf, props.conf, transforms.conf
- B. web.conf, props.conf, transforms.conf
- C. inputs.conf, props.conf, transforms.conf
- D. eventtypes.conf, indexes.conf, tags.conf
Correct answer: A
Explanation
The correct answer is A because indexes.conf, props.conf, and transforms.conf are essential files for configuring Splunk indexers. Options B, C, and D contain files that may not be relevant to indexer configuration or are used for different purposes within Splunk.