ExamGecko
Question list
Search
Search

Question 88 - SPLK-1003 discussion

Report
Export

Which of the following accurately describes HTTP Event Collector indexer acknowledgement?

A.
It requires a separate channel provided by the client.
Answers
A.
It requires a separate channel provided by the client.
B.
It is configured the same as indexer acknowledgement used to protect in-flight data.
Answers
B.
It is configured the same as indexer acknowledgement used to protect in-flight data.
C.
It can be enabled at the global setting level.
Answers
C.
It can be enabled at the global setting level.
D.
It stores status information on the Splunk server.
Answers
D.
It stores status information on the Splunk server.
Suggested answer: A

Explanation:

https://docs.splunk.com/Documentation/Splunk/8.2.2/Data/AboutHECIDXAck

- Section: About channels and sending data

Sending events to HEC with indexer acknowledgment active is similar to sending them with the setting off. There is one crucial difference: when you have indexer acknowledgment turned on, you must specify a channel when you send events. The concept of a channel was introduced in HEC primarily to prevent a fast client from impeding the performance of a slow client. When you assign one channel per client, because channels are treated equally on Splunk Enterprise, one client can't affect another. You must include a matching channel identifier both when sending data to HEC in an HTTP request and when requesting acknowledgment that events contained in the request have been indexed. If you don't, you will receive the error message, "Data channel is missing." Each request that includes a token for which indexer acknowledgment has been enabled must include a channel identifier, as shown in the following example cURL statement, where <data> represents the event data portion of the request

asked 23/09/2024
Manoj Balan
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first