Splunk Enterprise Security Certified Analyst — Question 36

As a best practice which of the following should be used to ingest data on clustered indexers?

Answer options

Correct answer: B

Explanation

Option B is correct because it specifies using modular inputs and the HTTP Event Collector (HEC), which are optimal for data ingestion in clustered environments. The other options either miss key components necessary for effective ingestion or suggest methods that are less efficient for clustered indexers.