SPLK-2002(205Q) · Question #71
Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)
Installing Splunk Enterprise Security on a Search Head Cluster follows a specific workflow: B, C, and D are correct. You first install ES on a staging instance (a standalone Splunk instance) because ES cannot be installed directly on a live cluster member - the installer…
Question
Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)
Options
- AInstall Enterprise Security on the deployer.
- BInstall Enterprise Security on a staging instance.
- CCopy the Enterprise Security configurations to the deployer.
- DUse the deployer to deploy Enterprise Security to the cluster members.
Explanation
Installing Splunk Enterprise Security on a Search Head Cluster follows a specific workflow: B, C, and D are correct. You first install ES on a staging instance (a standalone Splunk instance) because ES cannot be installed directly on a live cluster member - the installer generates and configures the necessary app files there. Once configured, you copy those app configurations to the deployer's shcluster/apps directory, and then use the deployer to push them out to all cluster members via splunk apply shcluster-bundle.
A is wrong because the deployer is a configuration distribution mechanism, not a Splunk search instance - you never install or run ES apps on it directly. The deployer holds configurations but does not itself participate in searching.
Memory tip: Think of it as a "stage, package, ship" model - stage on a test instance, package by copying to the deployer, ship via bundle push to the cluster. The deployer is just a mailbox, not a workstation.
Topics
Community Discussion
No community discussion yet for this question.