Splunk Enterprise Security Certified Admin — Question 89
At what point in the ES installation process should Splunk_TA_ForIndexers.spl be deployed to the indexers?
Answer options
- A. When adding apps to the deployment server.
- B. Splunk_TA_ForIndexers.spl is installed first.
- C. After installing ES on the search head(s) and running the distributed configuration management tool.
- D. Splunk_TA_ForIndexers.spl is only installed on indexer cluster sites using the cluster master and the splunk apply cluster-bundle command.
Correct answer: C
Explanation
The correct answer is C because Splunk_TA_ForIndexers.spl needs to be deployed after the Enterprise Security (ES) has been configured on the search heads to ensure proper functionality. Options A and B are incorrect as they do not reflect the correct timing in the installation sequence, and option D is also incorrect because it limits the deployment to only cluster sites, which is not the case for all installations.