Exam SPLK-1003 All QuestionsBrowse all questions from this exam
Question 2

The universal forwarder has which capabilities when sending data? (Choose all that apply.)

    Correct Answer: B, D

    The universal forwarder has the capability to compress data before sending it. This helps in reducing the bandwidth usage while transmitting data to the receiving indexers. Additionally, the universal forwarder supports indexer acknowledgement, which ensures that the receipt of data has been confirmed by the indexer, thereby guaranteeing data integrity and completeness in the indexing process.

Discussion
Ashton_98Option: B

D AND B Compressing data is the answer.

newrose

I agree

PrinceeOptions: BD

B and D both: compressed=true This tells the forwarder to compress the data before it forwards the data to receiving indexers in the target groups. If you set compressed to "false", the forwarder sends raw data. Splunk doc: https://docs.splunk.com/Documentation/Forwarder/8.1.1/Forwarder/Configureforwardingwithoutputs.conf#:~:text=compressed%3Dtrue%20This%20tells%20the,the%20forwarder%20sends%20raw%20data.

RedYetiOption: D

B. Compressing data D. Indexer acknowledgement System Admin course, page 182

emlchOptions: BD

UF has the following capabilities: - Index ack* (useACK=true in outputs.conf) - Send data over HTTP - Compressing the feed (compressed = true on both input.conf (indexer) and outputs.conf (uf)) - Securing the feed with SSL So, D and B C. that would be a HF A. not sure if Forwarders in general can send alerts

emlch

But definetely (a) the UF can't send alerts

ZeusP

Ans is B&D

Marco63

B AND D !!!

ApisOption: D

B and D are correct

leteke9429Option: B

The capabilities of a universal forwarder when sending data include: B. Compressing data D. Indexer acknowledgement Explanation: - **Compressing data**: Universal forwarders can compress data before sending it to reduce bandwidth usage. - **Indexer acknowledgement**: They can confirm receipt of data by the indexer to ensure data integrity and completeness in the indexing process. < https://bitly.cx/NyKD > I passed my SPLK exam with ease thanks to you. The dumps were accurate and the explanations were clear.

dohateloOption: B

B and D is correct . C(masking) can be done with the Heavy Forwarder not the Universal. Universal only parses data.

bobixakaOption: B

B and D are correct

IbiscOption: C

I think C is also correct. https://docs.splunk.com/Documentation/Splunk/latest/Data/Anonymizedata "To anonymize data with Splunk Enterprise, you must configure a Splunk Enterprise instance as a heavy forwarder and anonymize the incoming data with that instance before sending it to Splunk Enterprise."

Mntman77

In this case they are referring to "universal forwarder" not a heavy, so "C" is out.

harrytbbOption: D

B & D are the answers

Ailen_ManOption: B

Answer is B

BMO

Data Admin - Slide 65