SPLK-1003 Exam QuestionsBrowse all questions from this exam

SPLK-1003 Exam - Question 71


The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require multiple indexers. Following best practices, which types of

Splunk component instances are needed?

Show Answer
Correct Answer: BC

To handle the volume of data from collecting log files from 50 Linux servers and 200 Windows servers, the necessary Splunk component instances include indexers for data storage and indexing, a search head for managing and processing search requests, a deployment server for centralized management of configurations, a license master for managing Splunk licenses centrally, and universal forwarders for data forwarding. This setup adheres to best practices for large-scale data ingestion and search operations.

Discussion

13 comments
Sign in to comment
roblawOption: C
Nov 12, 2020

C. All search heads and indexers should use a license master

SplunkvOption: A
Apr 19, 2021

Did anybody notice that "s" is missing from "universal forwarder" in option C. whereas all other components are given as plural. so I would go with A.

hsingOption: B
Dec 2, 2020

B, since the license master can reside on the search head/deployment instance

Racgud
Dec 4, 2020

Wrong, C i correct

Ashton_98
Dec 11, 2020

Because it asks for 'component', it doesn't matter where it sits.

Robo187
Apr 19, 2021

I would add two heavy forwarders as intermediate forwarders for each linux and unix inputs

toney_mu
Feb 17, 2023

You may add for better design, but its not necessary

Hudda
Jul 7, 2021

what is the final answer here pls confirm friends :)

toney_mu
Feb 17, 2023

C option

nupacniyiveliOption: C
Jul 31, 2022

C is correct

kolaturkaOption: C
Apr 4, 2023

Option C is the correct answer. According to best practices, a distributed deployment architecture is recommended for large-scale data ingestion and search operations. In this scenario, the volume of data from 50 Linux servers and 200 Windows servers requires multiple indexers, a search head, a deployment server, a license master, and universal forwarders. The indexers are responsible for storing and indexing the data, while the search head is responsible for managing and processing search requests. The deployment server is used to centrally manage configurations across multiple components in the deployment, and the license master is used to centrally manage Splunk licenses. Finally, the universal forwarder is installed on the servers that generate the data to forward the data to the indexers.

Sandy_1988Option: C
Dec 16, 2020

I think C is the correct answer

loky0Option: C
Aug 26, 2021

I'd say C. License master is definitely recommended with multiple indexers. Since we have multiple servers, we’ll likely use a lot of UFs, so deployment servers will be good to monitor UFs.

BlueRoseliaOption: C
Feb 28, 2022

C System Admin module 9 pg 196

cagdaskarabagOption: A
Jul 30, 2022

https://community.splunk.com/t5/Knowledge-Management/The-volume-of-data-from-collecting-log-files-from-50-Linux/m-p/522684 Answer is A.

erick165Option: B
Mar 23, 2023

B is the correct one because it says needed, the license master and the HF are recomendations for best practice but not needed. also the option B as the UFs in plural and the opcion C doesn't

allahsalOption: C
Mar 1, 2024

https://community.splunk.com/t5/Knowledge-Management/The-volume-of-data-from-collecting-log-files-from-50-Linux/m-p/522684