QuestionQ30

Multisite Indexer Cluster

Which of the following can be used to configure a multi-site indexer cluster? (Select all that apply.)

Choose two
  • A Via Splunk Web.
  • B Directly edit SPLUNK_HOME/etc/system/local/server.conf
  • C Run a splunk edit cluster-config command from the CLI.
  • D Directly edit SPLUNK_HOME/etc/system/default/server.conf
Explanation

A multisite indexer cluster must be configured either by editing each node’s local server.conf file under SPLUNK_HOME/etc/system/local/ or by using the splunk edit cluster-config CLI command. Splunk Web is not supported for multisite cluster deployment, and SPLUNK_HOME/etc/system/default/server.conf is not the local configuration file for these settings.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!