A Splunk architect has inherited the Splunk deployment at Buttercup Games and end users are complaining that the events are inconsistently formatted for a web sourcetype. Further investigation reveals that not all web logs flow through the same infrastructure: some of the data goes through heavy forwarders and some of the forwarders are managed by another department. Which of the following items might be the cause for this issue?
A) The search head may have different configurations than the indexers.
B) The data inputs are not properly configured across all the forwarders.
C) The indexers may have different configurations than the heavy forwarders.
D) The forwarders managed by the other department are an older version than the rest.
Correct Answer:
Verified
Q5: To activate replication for an index in
Q6: Which Splunk server role regulates the functioning
Q7: Which of the following security options must
Q8: What does the deployer do in a
Q9: Which CLI command converts a Splunk instance
Q11: Which of the following clarification steps should
Q12: Which component in the splunkd.log will log
Q13: Which index-time props.conf attributes impact indexing performance?
Q14: When using the props.conf LINE_BREAKER attribute to
Q15: Which of the following is a good
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents