Splunk Enterprise Security Certified Analyst — Question 68

Where are Splunk Data Model Acceleration (DMA) summaries stored?

Answer options

Correct answer: A

Explanation

The correct answer is A, as DMA summaries are specifically stored in the tstatsHomePath. Option B is incorrect because .tsidx files are used for indexed data, not DMA summaries. Option C is not accurate since summaryHomePath does not specifically refer to DMA summary storage, and option D is also wrong as journal.gz pertains to the internal logs, not DMA summaries.