ExamGecko
Question list
Search
Search

Question 179 - SPLK-1003 discussion

Report
Export

Syslog files are being monitored on a Heavy Forwarder.

Where would the appropriate TRANSFORMS setting be deployed to reroute logs based on the event message?

A.
Heavy Forwarder
Answers
A.
Heavy Forwarder
B.
Indexer
Answers
B.
Indexer
C.
Search head
Answers
C.
Search head
D.
Deployment server
Answers
D.
Deployment server
Suggested answer: A

Explanation:

A Heavy Forwarder is a Splunk instance that can parse and filter data before forwarding it to another Splunk instance, such as an indexer1.A Heavy Forwarder can also perform index-time field extractions using the TRANSFORMS setting2.

The TRANSFORMS setting is used to configure data transformations in the transforms.conf file3.The transforms.conf file contains settings and values that you can use to configure host and source type overrides, anonymize sensitive data, route events to different indexes, create index-time and search-time field extractions, and set up lookup tables3.

The TRANSFORMS setting can be deployed to the Heavy Forwarder where the syslog files are being monitored, so that the logs can be rerouted based on the event message before they are forwarded to the indexer2.This can improve the performance and efficiency of data processing and indexing2.

asked 23/09/2024
Alberto Castillo
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first