Splunk Enterprise Security Certified Admin — Question 89

At what point in the ES installation process should Splunk_TA_ForIndexers.spl be deployed to the indexers?

Answer options

Correct answer: C

Explanation

The correct answer is C because Splunk_TA_ForIndexers.spl needs to be deployed after the Enterprise Security (ES) has been configured on the search heads to ensure proper functionality. Options A and B are incorrect as they do not reflect the correct timing in the installation sequence, and option D is also incorrect because it limits the deployment to only cluster sites, which is not the case for all installations.