SPLK-2002 Exam QuestionsBrowse all questions from this exam

SPLK-2002 Exam - Question 37


A new Splunk customer is using syslog to collect data from their network devices on port 514. What is the best practice for ingesting this data into Splunk?

Show Answer
Correct Answer: D

The best practice for ingesting syslog data into Splunk is to configure syslog to write logs to files and then use a Splunk forwarder to collect and forward those logs to the Splunk indexers. This approach ensures reliable data ingestion and better handling of high volumes of data, as it allows the forwarder to manage data forwarding efficiently and offers better error handling and buffering capabilities.

Discussion

5 comments
Sign in to comment
david88fOption: D
Oct 30, 2021

Answer is: D

demarko
Dec 9, 2020

https://wiki.splunk.com/Community:BestPracticeForConfiguringSyslogInput

RedYetiOption: D
Apr 26, 2022

Answer D

Vale5MOption: D
Mar 13, 2023

Answer is D. Show Data Admin slide 147

qtygbapjpesdayazkoOption: D
Jun 7, 2023

D. Configure syslog to write logs and use a Splunk forwarder to collect the logs.