Exam SPLK-1003 All QuestionsBrowse all questions from this exam
Question 22

Which Splunk forwarder type allows parsing of data before forwarding to an indexer?

    Correct Answer: C

    The correct answer is the Heavy forwarder. In Splunk, a heavy forwarder is capable of parsing data before forwarding it to an indexer. It can perform filtering, routing, and modification of data, unlike the universal forwarder which simply forwards raw data without parsing. The heavy forwarder provides the capability to process and transform the data at the source.

Discussion
Fe01

That has already been asked in question 7

ApisOption: C

C is correct

thomassOption: C

Answer : C

ucsdmiami2020

Agreed C. Quoting the Splunk reference URL https://docs.splunk.com/Documentation/Splunk/8.2.2/Forwarding/Typesofforwarders "A heavy forwarder is a full Splunk Enterprise instance that can index, search, and change data as well as forward it. The heavy forwarder has some features disabled to reduce system resource usage."

AsamiOption: C

C. Heavy forwarde