SPLK-1003 · Question #105
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any…
The correct answer is D. Search head. Adding a dedicated Search Head for the Compliance Department is the correct solution. A search head is the Splunk component that manages knowledge objects such as reports, dashboards, saved searches, and field extractions. By giving the Compliance team their own isolated search…
Question
Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?
Options
- AIndexer
- BDeployment server
- CUniversal forwarder
- DSearch head
How the community answered
(40 responses)- B5% (2)
- C3% (1)
- D93% (37)
Explanation
Adding a dedicated Search Head for the Compliance Department is the correct solution. A search head is the Splunk component that manages knowledge objects such as reports, dashboards, saved searches, and field extractions. By giving the Compliance team their own isolated search head, their knowledge objects are completely separated from other users. Permissions and access controls on a dedicated search head ensure that other users cannot see the Compliance team's reports or knowledge objects. An Indexer (A) stores data but does not control knowledge object visibility. A Deployment Server (B) manages app/config deployment. A Universal Forwarder (C) only collects and forwards data.
Topics
Community Discussion
No community discussion yet for this question.