Splunk Enterprise Certified Admin Practice Test

Disable ads (and more) with a membership for a one time $2.99 payment

Prepare for the Splunk Enterprise Certified Admin Exam with comprehensive quizzes. Enhance your skills with multiple choice questions, detailed explanations, and study resources. Get exam-ready today!

Each practice test/flash card set has 50 randomly selected questions from a bank of over 500. You'll get a new set of questions each time!

Practice this question and more.


On a deployment server, apps are added to which directory?

  1. Splunk.Home/etc/system/default

  2. Splunk.Home/etc/deployment-apps

  3. Splunk.Home/etc/apps

  4. Splunk.Home/etc/system/local

The correct answer is: Splunk.Home/etc/deployment-apps

The correct answer is that apps are added to the Splunk.Home/etc/deployment-apps directory on a deployment server. This specific directory is designed for storing applications intended for distribution to other Splunk instances that are part of the deployment. When you place apps in the deployment-apps directory, the deployment server can push these apps to the clients (or forwarders) based on their configurations specified in the deployment server's serverclass.conf file. This mechanism ensures that the intended apps are deployed consistently across multiple instances in your Splunk environment. In contrast, the other directories serve different purposes. The system/default directory contains default configuration files that come with Splunk and should not be modified directly, as changes here can be overwritten during upgrades. Meanwhile, the etc/apps directory is primarily for local apps that are installed directly on that server instance rather than being distributed from a deployment server. The system/local directory is intended for local configuration modifications specific to that instance, which would also not typically be where you place apps for deployment due to its role in holding local configurations and overrides.