ExamGecko
Question list
Search
Search

List of questions

Search

Question 146 - SPLK-2002 discussion

Report
Export

Which of the following is true for indexer cluster knowledge bundles?

A.

Only app-name/local is pushed.

Answers
A.

Only app-name/local is pushed.

B.

app-name/default and app-name/local are merged before pushing.

Answers
B.

app-name/default and app-name/local are merged before pushing.

C.

Only app-name/default is pushed.

Answers
C.

Only app-name/default is pushed.

D.

app-name/default and app-name/local are pushed without change.

Answers
D.

app-name/default and app-name/local are pushed without change.

Suggested answer: B

Explanation:

According to the Splunk documentation1, indexer cluster knowledge bundles are the configuration files that the cluster master distributes to the peer nodes as part of the cluster configuration bundle. The knowledge bundles contain the knowledge objects, such as event types, tags, lookups, and so on, that are relevant for indexing and searching the data. The cluster master creates the knowledge bundles by merging the app-name/default and app-name/local directories from the apps that reside on the master node.The cluster master then pushes the knowledge bundles to the peer nodes, where they reside under the $SPLUNK_HOME/var/run directory2. The other options are false because:

Only app-name/local is pushed. This is false because the cluster master pushes both the app-name/default and app-name/local directories, after merging them, to the peer nodes.The app-name/local directory contains the local customizations of the app configuration, while the app-name/default directory contains the default app configuration3.

Only app-name/default is pushed. This is false because the cluster master pushes both the app-name/default and app-name/local directories, after merging them, to the peer nodes.The app-name/default directory contains the default app configuration, while the app-name/local directory contains the local customizations of the app configuration3.

app-name/default and app-name/local are pushed without change. This is false because the cluster master merges the app-name/default and app-name/local directories before pushing them to the peer nodes.This ensures that the peer nodes have the latest and consistent configuration of the apps3.

asked 13/11/2024
Luis Hernaiz
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first