SPLK-2002(205Q) · Question #134
What information is needed about the current environment before deploying Splunk? (select all that apply)
Before deploying Splunk, knowing the overall goals (B), key users (C), and data sources (D) are all required - these three form the foundation of any Splunk deployment plan. Goals define what you're trying to achieve (security monitoring, compliance, IT ops), which directly…
Question
What information is needed about the current environment before deploying Splunk? (select all that apply)
Options
- AList of vendors for network devices.
- BOverall goals for the deployment.
- CKey users.
- DData sources.
Explanation
Before deploying Splunk, knowing the overall goals (B), key users (C), and data sources (D) are all required - these three form the foundation of any Splunk deployment plan. Goals define what you're trying to achieve (security monitoring, compliance, IT ops), which directly shapes how Splunk is sized and configured. Key users determine what dashboards, roles, and access controls are needed, while data sources dictate which inputs, forwarders, and indexes must be configured - without knowing your data sources, you cannot meaningfully deploy Splunk at all.
A is incorrect because the specific vendor of a network device is not necessary pre-deployment information; what matters is the data those devices produce (logs, metrics), not who manufactured them. Vendor lists belong to procurement or asset management, not Splunk architecture planning.
Memory tip: Think of B, C, D as answering the three core questions - Why are we deploying? (Goals), Who will use it? (Key users), What will it ingest? (Data sources). If you can't answer all three, you're not ready to deploy.
Topics
Community Discussion
No community discussion yet for this question.