nerdexam
Splunk

SPLK-2002(205Q) · Question #71

Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)

Installing Splunk Enterprise Security on a Search Head Cluster follows a specific workflow: B, C, and D are correct. You first install ES on a staging instance (a standalone Splunk instance) because ES cannot be installed directly on a live cluster member - the installer…

Splunk App Management

Question

Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)

Options

  • AInstall Enterprise Security on the deployer.
  • BInstall Enterprise Security on a staging instance.
  • CCopy the Enterprise Security configurations to the deployer.
  • DUse the deployer to deploy Enterprise Security to the cluster members.

Explanation

Installing Splunk Enterprise Security on a Search Head Cluster follows a specific workflow: B, C, and D are correct. You first install ES on a staging instance (a standalone Splunk instance) because ES cannot be installed directly on a live cluster member - the installer generates and configures the necessary app files there. Once configured, you copy those app configurations to the deployer's shcluster/apps directory, and then use the deployer to push them out to all cluster members via splunk apply shcluster-bundle.

A is wrong because the deployer is a configuration distribution mechanism, not a Splunk search instance - you never install or run ES apps on it directly. The deployer holds configurations but does not itself participate in searching.

Memory tip: Think of it as a "stage, package, ship" model - stage on a test instance, package by copying to the deployer, ship via bundle push to the cluster. The deployer is just a mailbox, not a workstation.

Topics

#Enterprise Security#Search Head Cluster#deployer#app installation

Community Discussion

No community discussion yet for this question.

Full SPLK-2002(205Q) Practice