nerdexam
Splunk

SPLK-2002(205Q) · Question #175

(Which of the following must be included in a deployment plan?)

The correct answer is C. Current logging details and data source inventory. According to Splunk's Deployment Planning and Implementation Guidelines, one of the most critical elements of a Splunk deployment plan is a comprehensive data source inventory and current logging details. This information defines the scope of data ingestion and directly…

Architect Planning and Design

Question

(Which of the following must be included in a deployment plan?)

Options

  • AFuture topology diagrams of the IT environment.
  • BA comprehensive list of stakeholders, either direct or indirect.
  • CCurrent logging details and data source inventory.
  • DBusiness continuity and disaster recovery plans.

How the community answered

(45 responses)
  • A
    7% (3)
  • B
    4% (2)
  • C
    87% (39)
  • D
    2% (1)

Explanation

According to Splunk's Deployment Planning and Implementation Guidelines, one of the most critical elements of a Splunk deployment plan is a comprehensive data source inventory and current logging details. This information defines the scope of data ingestion and directly influences sizing, architecture design, and licensing. A proper deployment plan should identify: All data sources (such as syslogs, application logs, network devices, OS logs, databases, etc.) Expected daily ingest volume per source Log formats and sourcetypes Retention requirements and compliance constraints This data forms the foundation for index sizing, forwarder configuration, and storage planning. Without a well-defined data inventory, Splunk architects cannot accurately determine hardware capacity, indexing load, or network throughput requirements. While stakeholder mapping, topology diagrams, and continuity plans (Options A, B, D) are valuable in a broader IT project, Splunk's official guidance emphasizes logging details and source inventory as mandatory for a deployment plan. It ensures that the Splunk environment is properly sized, licensed, and aligned with business data visibility goals. - Splunk Enterprise Deployment Planning Manual - Data Source Inventory Requirements - Capacity Planning for Indexer and Search Head Sizing - Planning Data Onboarding and Ingestion Strategies - Splunk Architecture and Implementation Best Practices

Topics

#deployment planning#data source inventory#requirements gathering#architecture planning

Community Discussion

No community discussion yet for this question.

Full SPLK-2002(205Q) Practice