SPLK-2002 Exam QuestionsBrowse all questions from this exam

SPLK-2002 Exam - Question 4


A Splunk architect has inherited the Splunk deployment at Buttercup Games and end users are complaining that the events are inconsistently formatted for a web sourcetype. Further investigation reveals that not all web logs flow through the same infrastructure: some of the data goes through heavy forwarders and some of the forwarders are managed by another department.

Which of the following items might be the cause for this issue?

Show Answer
Correct Answer: BC

The issue is likely that the data inputs are not properly configured across all the forwarders. In a scenario where multiple forwarders are involved, inconsistently formatted events usually indicate discrepancies in how data inputs are set up on each forwarder. If some forwarders have different configurations or are not configured to handle the data uniformly, it can lead to inconsistent data formatting.

Discussion

5 comments
Sign in to comment
sadhkaOption: B
Sep 11, 2020

I think answer is B, Why the configuration of indexer and Heavy forwarder should be same.

mker
Sep 30, 2020

The correct answer is C. Alternative B cannot be since the UFs cannot be configured in the props.conf and neither does it contemplate the indexers.

RichLV
Apr 14, 2021

Question does not specify whether other forwarders are UFs. It only mentions heavy forwarders. Could be B.

mker
Jun 30, 2021

For there to be a correct parsing of the data in the indexers and heavy forwarders, the same configuration must be used.

SPLTony
Sep 30, 2023

That's not true. Props.conf can indeed be in Universal Forwarders. For example, EVENT_BREAKER properties are ONLY applicable in props.conf on UFs. https://docs.splunk.com/Documentation/ITSI/4.17.0/Configure/props.conf

manu78Option: C
Mar 11, 2021

C is the correct Answer

sutcocukOption: C
Mar 31, 2022

C is correct

sutcocukOption: C
Mar 22, 2022

C is correct

UntakedOption: B
Jan 25, 2024

It's the B since they mention that the reason of the issue is that sourcetype if the only affecting the data which means that some inputs could have a wrong sourcetype name in the inputs.conf

bobixaka
Feb 1, 2024

Nope. We are talking about the same sourcetype, different parsing/format here.