Splunk Enterprise Security Certified Analyst — Question 28
A Splunk Index cluster is being installed and the indexers need to be configured with a license master. After the customer provides the name of the license master, what is the next step?
Answer options
- A. Enter the license master configuration via Splunk web on each indexer before disabling Splunk web.
- B. Update /opt/splunk/etc/master-apps/_cluster/default/server.conf on the cluster master and apply a cluster bundle.
- C. Update the Splunk PS base config license app and copy to each indexer.
- D. Update the Splunk PS base config license app and deploy via the cluster master.
Correct answer: D
Explanation
The correct answer is D because updating the Splunk PS base config license app and deploying it via the cluster master ensures that all indexers in the cluster receive the necessary license configuration efficiently. Options A and C do not utilize the cluster master for deployment, which is less effective in managing a large number of indexers, while option B incorrectly suggests modifying server.conf instead of focusing on the license app.