Exam SPLK-1003 All QuestionsBrowse all questions from this exam
Question 87

In a distributed environment, which Splunk component is used to distribute apps and configurations to the other Splunk instances?

    Correct Answer: D

    In a distributed Splunk environment, the deployment server is the component responsible for distributing apps and configurations to other Splunk instances, such as forwarders. The deployment server manages the deployment of configuration files to the client instances, allowing for centralized management of configuration updates across multiple instances. This ensures that all instances in the environment stay consistent with the desired configuration.

Discussion
Shaq007Option: D

D. Deployment server https://docs.splunk.com/Documentation/Splunk/8.0.5/Updating/Updateconfigurations First line says it all: "The deployment server distributes deployment apps to clients."

not_another_user_007Option: D

The answer is D as it is asking about deploying apps to other Splunk instances (assuming it is UFs/HFs) If the question was asking what component sends data to the Search Head Cluster, then it would be a deployer. As admins (hence this exam) does not look at SHC, the answer would be D

mybox1Option: D

D is correct

ComeUpOption: B

The correct answer is B. https://docs.splunk.com/Documentation/Splunk/8.2.4/DistSearch/PropagateSHCconfigurationchanges

kirtakOption: D

Distributed, not clustered, so D for forwarder management

mngeshaOption: D

Deployment server. Answer is D.

appopayOption: B

Since the question is specifically about a distributed environment, I'd say the awaited response is: Deployer

pucca012Option: D

A deployer is used to deploy apps to a search head cluster. A cluster master is used to deploy apps and manage replication within an indexer cluster (single or multi-site) A deployment server is used to deploy apps to forwarders (and technically could be used to deploy apps to other Splunk servers as well but with a number of caveats)

Splunkv

so answer is B & D, correct?

Splunkv

The deployer is a Splunk Enterprise instance that you use to distribute apps and certain other configuration updates to search head cluster members. The set of updates that the deployer distributes is called the configuration bundle. https://docs.splunk.com/Documentation/Splunk/8.1.3/DistSearch/PropagateSHCconfigurationchanges#:~:text=The%20deployer%20is%20a%20Splunk,is%20called%20the%20configuration%20bundle.

BlueRoselia

Yes Answer D & B If I have to choose one, I will choose D because the system admin and data admin talks mainly about the deployment server. diagrams with the deployer are shown but not discussed

anonyuser

It is not talking about a cluster here

newrose

I dont think that answer is correct