Splunk Enterprise Security Certified Analyst — Question 23

The customer wants to migrate their current Splunk Index cluster to new hardware to improve indexing and search performance. What is the correct process and procedure for this task?

Answer options

Correct answer: D

Explanation

Option D is correct because it ensures that the new indexers are properly configured to receive the cluster bundle and maintain the same settings as the original peers, while also including the necessary steps to update forwarders and decommission old peers. Options A and C fail to mention the cluster bundle, which is crucial for proper setup, and option B does not follow the correct order of operations, as it suggests removing old peers before updating forwarders.