ExamGecko
Question list
Search
Search

List of questions

Search

Question 160 - SPLK-2002 discussion

Report
Export

When should a Universal Forwarder be used instead of a Heavy Forwarder?

A.

When most of the data requires masking.

Answers
A.

When most of the data requires masking.

B.

When there is a high-velocity data source.

Answers
B.

When there is a high-velocity data source.

C.

When data comes directly from a database server.

Answers
C.

When data comes directly from a database server.

D.

When a modular input is needed.

Answers
D.

When a modular input is needed.

Suggested answer: B

Explanation:

According to the Splunk blog1, the Universal Forwarder is ideal for collecting data from high-velocity data sources, such as a syslog server, due to its smaller footprint and faster performance. The Universal Forwarder performs minimal processing and sends raw or unparsed data to the indexers, reducing the network traffic and the load on the forwarders. The other options are false because:

When most of the data requires masking, a Heavy Forwarder is needed, as it can perform advanced filtering and data transformation before forwarding the data2.

When data comes directly from a database server, a Heavy Forwarder is needed, as it can run modular inputs such as DB Connect to collect data from various databases2.

When a modular input is needed, a Heavy Forwarder is needed, as the Universal Forwarder does not include a bundled version of Python, which is required for most modular inputs2.

asked 13/11/2024
Henock Asmerom
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first