ExamGecko
Question list
Search
Search

Question 53 - SPLK-1003 discussion

Report
Export

When running a real-time search, search results are pulled from which Splunk component?

A.
Heavy forwarders and search peers
Answers
A.
Heavy forwarders and search peers
B.
Heavy forwarders
Answers
B.
Heavy forwarders
C.
Search heads
Answers
C.
Search heads
D.
Search peers
Answers
D.
Search peers
Suggested answer: D

Explanation:

Using the Splunk reference URL https://docs.splunk.com/Splexicon:Searchpeer

"search peer is a splunk platform instance that responds to search requests from a search head. The term "search peer" is usally synonymous with the indexer role in a distributed search topology.

However, other instance types also have access to indexed data, particularly internal diagnostic data, and thus function as search peers when they respond to search requests for that data."

asked 23/09/2024
Nader Pouri
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first