QuestionQ20
Forwarder and Deployment Best PracticesWhen is a Heavy Forwarder required rather than a Universal Forwarder?
- A To use Splunk TCP to forward event data.
- B To route event data to an indexer cluster.
- C To mask event data from Linux inputs prior to forwarding to indexers.
- D To change event host names based on the folder structure where the input is found.
Community Discussion