At what point in the ES installation process should Splunk_TA_ForIndexers.spl be deployed to the indexers?
At what point in the ES installation process should Splunk_TA_ForIndexers.spl be deployed to the indexers?
Splunk_TA_ForIndexers.spl should be deployed to the indexers after installing ES on the search head(s) and running the distributed configuration management tool. This ensures that the necessary configurations and knowledge objects are properly distributed and applied to the indexers, making sure that the environment is fully functional and consistent.
C is correct Admin ES - Slide 161
C is the Ans
C is correct
Splunk_TA_ForIndexers.spl is created only for clustered indexer environment https://docs.splunk.com/Documentation/ES/6.1.0/Install/InstallTechnologyAdd-ons#Create_the_Splunk_TA_ForIndexers_and_manage_deployment_manually
After installing Splunk Enterprise Security (ES) on the search head(s) and running the distributed configuration management tool, you should deploy Splunk_TA_ForIndexers.spl to the indexers. This ensures that the necessary configurations and knowledge objects are properly distributed and applied to the indexers.
Correct answer D ! See instructions from Admin ES: • Install ES on the Deployer 1. On the Splunk toolbar, select Apps > Manage Apps and click Install app from file 2. Click Choose File and select the Splunk Enterprise Security file 3. Click Upload to begin the installation 4. Click Continue to app setup page 5. Click Start Configuration Process, and wait for it to complete 6. Use the Deployer to deploy ES to the cluster members. From the Deployer run: splunk apply shcluster-bundle