SPLK-1003 Exam QuestionsBrowse all questions from this exam

SPLK-1003 Exam - Question 71


The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require multiple indexers. Following best practices, which types of

Splunk component instances are needed?

Show Answer
Correct Answer: C

To handle the volume of data from collecting log files from 50 Linux servers and 200 Windows servers, the necessary Splunk component instances include indexers for data storage and indexing, a search head for managing and processing search requests, a deployment server for centralized management of configurations, a license master for managing Splunk licenses centrally, and universal forwarders for data forwarding. This setup adheres to best practices for large-scale data ingestion and search operations.

Discussion

13 comments
Sign in to comment
roblaw
May 12, 2021

C. All search heads and indexers should use a license master

Splunkv
Oct 19, 2021

Did anybody notice that "s" is missing from "universal forwarder" in option C. whereas all other components are given as plural. so I would go with A.

hsing
Jun 2, 2021

B, since the license master can reside on the search head/deployment instance

Racgud
Jun 4, 2021

Wrong, C i correct

Ashton_98
Jun 11, 2021

Because it asks for 'component', it doesn't matter where it sits.

Robo187
Oct 19, 2021

I would add two heavy forwarders as intermediate forwarders for each linux and unix inputs

toney_mu
Aug 17, 2023

You may add for better design, but its not necessary

Hudda
Jan 7, 2022

what is the final answer here pls confirm friends :)

toney_mu
Aug 17, 2023

C option

BlueRoselia
Aug 28, 2022

C System Admin module 9 pg 196

nupacniyiveliOption: C
Feb 1, 2023

C is correct

kolaturka
Oct 4, 2023

Option C is the correct answer. According to best practices, a distributed deployment architecture is recommended for large-scale data ingestion and search operations. In this scenario, the volume of data from 50 Linux servers and 200 Windows servers requires multiple indexers, a search head, a deployment server, a license master, and universal forwarders. The indexers are responsible for storing and indexing the data, while the search head is responsible for managing and processing search requests. The deployment server is used to centrally manage configurations across multiple components in the deployment, and the license master is used to centrally manage Splunk licenses. Finally, the universal forwarder is installed on the servers that generate the data to forward the data to the indexers.

Sandy_1988
Jun 16, 2021

I think C is the correct answer

loky0
Feb 26, 2022

I'd say C. License master is definitely recommended with multiple indexers. Since we have multiple servers, we’ll likely use a lot of UFs, so deployment servers will be good to monitor UFs.

cagdaskarabag
Jan 31, 2023

https://community.splunk.com/t5/Knowledge-Management/The-volume-of-data-from-collecting-log-files-from-50-Linux/m-p/522684 Answer is A.

erick165Option: B
Sep 24, 2023

B is the correct one because it says needed, the license master and the HF are recomendations for best practice but not needed. also the option B as the UFs in plural and the opcion C doesn't

allahsalOption: C
Sep 1, 2024

https://community.splunk.com/t5/Knowledge-Management/The-volume-of-data-from-collecting-log-files-from-50-Linux/m-p/522684