nerdexam
Splunk

SPLK-2002(205Q) · Question #85

When Splunk is installed, where are the internal indexes stored by default?

The correct answer is B. SPLUNK_HOME/var/lib. Splunk internal indexes are the indexes that store Splunk's own data, such as internal logs, metrics, audit events, and configuration snapshots. By default, Splunk internal indexes are stored in the SPLUNK_HOME/var/lib/splunk directory, along with other user-defined indexes…

Splunk Architecture and Installation

Question

When Splunk is installed, where are the internal indexes stored by default?

Options

  • ASPLUNK_HOME/bin
  • BSPLUNK_HOME/var/lib
  • CSPLUNK_HOME/var/run
  • DSPLUNK_HOME/etc/system/default

How the community answered

(51 responses)
  • B
    94% (48)
  • C
    2% (1)
  • D
    4% (2)

Explanation

Splunk internal indexes are the indexes that store Splunk's own data, such as internal logs, metrics, audit events, and configuration snapshots. By default, Splunk internal indexes are stored in the SPLUNK_HOME/var/lib/splunk directory, along with other user-defined indexes. The SPLUNK_HOME/bin directory contains the Splunk executable files and scripts. The SPLUNK_HOME/var/run directory contains the Splunk process ID files and lock files. The SPLUNK_HOME/etc/system/default directory contains the default Splunk configuration files.

Topics

#internal indexes#SPLUNK_HOME#directory structure#default paths

Community Discussion

No community discussion yet for this question.

Full SPLK-2002(205Q) Practice