nerdexam
Splunk

SPLK-3002 · Question #24

When installing ITSI to support a Distributed Search Architecture, which of the following items apply? (Choose all that apply.)

The correct answer is A. Copy SA-IndexCreation to all indexers. A is the correct answer because when installing ITSI to support a distributed search architecture, you need to copy SA-IndexCreation to all indexers. SA-IndexCreation is an app that contains the definitions of the ITSI indexes, such as itsi_summary, itsi_tracked_alerts…

Splunk ITSI Concepts and Environment

Question

When installing ITSI to support a Distributed Search Architecture, which of the following items apply? (Choose all that apply.)

Options

  • ACopy SA-IndexCreation to all indexers.
  • BCopy SA-IndexCreation to the etc/apps directory on the index cluster master node.
  • CExtract installer package into etc/apps directory of the cluster deployer node.
  • DExtract ITSI app package into etc/apps directory of search head.

How the community answered

(49 responses)
  • A
    90% (44)
  • B
    2% (1)
  • C
    6% (3)
  • D
    2% (1)

Explanation

A is the correct answer because when installing ITSI to support a distributed search architecture, you need to copy SA-IndexCreation to all indexers. SA-IndexCreation is an app that contains the definitions of the ITSI indexes, such as itsi_summary, itsi_tracked_alerts, itsi_grouped_alerts, etc. You need to copy this app to all indexers to ensure that they can store and search the ITSI data.

Topics

#distributed search#SA-IndexCreation#cluster deployer#ITSI installation

Community Discussion

No community discussion yet for this question.

Full SPLK-3002 Practice