nerdexam
Splunk

SPLK-2002(205Q) · Question #202

A customer plans to have 20,000 Splunk-managed forwarders. What is a common step to ensure Splunk forwarder management performance is not impacted?

The correct answer is D. Ensure that server classes have no more than 5,000 deployment clients. Splunk Deployment Server documentation clearly states that server class scalability is a primary factor in managing large numbers of forwarders. Each server class contains one or more apps and targets a set of deployment clients. Splunk recommends limiting the number of…

Forwarder Management and Deployment Server

Question

A customer plans to have 20,000 Splunk-managed forwarders. What is a common step to ensure Splunk forwarder management performance is not impacted?

Options

  • AIncrease the phone-home interval for deployment clients.
  • BUse workload management to ensure client pools.
  • CReduce the polling interval for clients on the Deployment Server.
  • DEnsure that server classes have no more than 5,000 deployment clients.

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    6% (3)
  • D
    90% (47)

Explanation

Splunk Deployment Server documentation clearly states that server class scalability is a primary factor in managing large numbers of forwarders. Each server class contains one or more apps and targets a set of deployment clients. Splunk recommends limiting the number of deployment clients per server class to maintain responsiveness and avoid configuration bottlenecks. For large environments with tens of thousands of forwarders, Splunk explicitly advises splitting deployment clients across multiple server classes, typically in blocks of several thousand clients per class. This ensures that the Deployment Server can efficiently process configuration bundles, client check-ins, and app updates without delays or timeouts. Increasing the phone-home interval (option A) may reduce check-in frequency but does not address server class scalability. Workload management (option B) is unrelated to Deployment Server operations. Reducing polling intervals (option C) actually increases load and is discouraged at scale. Therefore, ensuring that server classes do not exceed approximately 5,000 deployment clients is the correct and recommended approach. Splunk Deployment Server Manual; Forwarder Management at Scale; Deployment Server Performance Best Practices.

Topics

#Deployment Server#server classes#forwarder management#scalability

Community Discussion

No community discussion yet for this question.

Full SPLK-2002(205Q) Practice