SPLK-1003 Exam QuestionsBrowse all questions from this exam

SPLK-1003 Exam - Question 2


The universal forwarder has which capabilities when sending data? (Choose all that apply.)

Show Answer
Correct Answer: BD

The universal forwarder has the capability to compress data before sending it. This helps in reducing the bandwidth usage while transmitting data to the receiving indexers. Additionally, the universal forwarder supports indexer acknowledgement, which ensures that the receipt of data has been confirmed by the indexer, thereby guaranteeing data integrity and completeness in the indexing process.

Discussion

14 comments
Sign in to comment
Ashton_98Option: B
Nov 15, 2020

D AND B Compressing data is the answer.

newrose
Nov 30, 2020

I agree

PrinceeOptions: BD
Feb 5, 2021

B and D both: compressed=true This tells the forwarder to compress the data before it forwards the data to receiving indexers in the target groups. If you set compressed to "false", the forwarder sends raw data. Splunk doc: https://docs.splunk.com/Documentation/Forwarder/8.1.1/Forwarder/Configureforwardingwithoutputs.conf#:~:text=compressed%3Dtrue%20This%20tells%20the,the%20forwarder%20sends%20raw%20data.

RedYetiOption: D
Mar 24, 2022

B. Compressing data D. Indexer acknowledgement System Admin course, page 182

ZeusP
May 25, 2021

Ans is B&D

emlchOptions: BD
Sep 5, 2022

UF has the following capabilities: - Index ack* (useACK=true in outputs.conf) - Send data over HTTP - Compressing the feed (compressed = true on both input.conf (indexer) and outputs.conf (uf)) - Securing the feed with SSL So, D and B C. that would be a HF A. not sure if Forwarders in general can send alerts

emlch
Sep 5, 2022

But definetely (a) the UF can't send alerts

ApisOption: D
Dec 30, 2021

B and D are correct

Marco63
Apr 22, 2022

B AND D !!!

BMO
May 29, 2021

Data Admin - Slide 65

Ailen_ManOption: B
May 10, 2022

Answer is B

harrytbbOption: D
Feb 6, 2023

B & D are the answers

IbiscOption: C
Jun 17, 2023

I think C is also correct. https://docs.splunk.com/Documentation/Splunk/latest/Data/Anonymizedata "To anonymize data with Splunk Enterprise, you must configure a Splunk Enterprise instance as a heavy forwarder and anonymize the incoming data with that instance before sending it to Splunk Enterprise."

Mntman77
Jun 26, 2023

In this case they are referring to "universal forwarder" not a heavy, so "C" is out.

bobixakaOption: B
Nov 2, 2023

B and D are correct

dohateloOption: B
Apr 9, 2024

B and D is correct . C(masking) can be done with the Heavy Forwarder not the Universal. Universal only parses data.

leteke9429Option: B
Jun 29, 2024

The capabilities of a universal forwarder when sending data include: B. Compressing data D. Indexer acknowledgement Explanation: - **Compressing data**: Universal forwarders can compress data before sending it to reduce bandwidth usage. - **Indexer acknowledgement**: They can confirm receipt of data by the indexer to ensure data integrity and completeness in the indexing process. < https://bitly.cx/NyKD > I passed my SPLK exam with ease thanks to you. The dumps were accurate and the explanations were clear.