ExamGecko
Question list
Search
Search

Question 25 - SPLK-1003 discussion

Report
Export

Which configuration file would be used to forward the Splunk internal logs from a search head to the indexer?

A.
props.conf
Answers
A.
props.conf
B.
inputs.conf
Answers
B.
inputs.conf
C.
outputs.conf
Answers
C.
outputs.conf
D.
collections.conf
Answers
D.
collections.conf
Suggested answer: C

Explanation:

https://docs.splunk.com/Documentation/Splunk/8.1.1/DistSearch/Forwardsearchheaddata

Per the provided Splunk reference URL by @hwangho, scroll to section Forward search head data, subsection titled, 2. Configure the search head as a forwarder. "Create an outputs.conf file on the search head that configures the search head for load-balanced forwarding across the set of search peers (indexers)."

Reference: https://community.splunk.com/t5/Getting-Data-In/How-to-configure-search-head-toforwardinternal-data-to-the/td-p/111658

asked 23/09/2024
Alan Phillips
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first