QuestionQ20

Forwarder and Deployment Best Practices

When is a Heavy Forwarder required rather than a Universal Forwarder?

  • A To use Splunk TCP to forward event data.
  • B To route event data to an indexer cluster.
  • C To mask event data from Linux inputs prior to forwarding to indexers.
  • D To change event host names based on the folder structure where the input is found.
Explanation

Masking event content before it is forwarded requires parsing and event-level transformation. A Heavy Forwarder can parse and transform events before forwarding; a Universal Forwarder generally forwards unparsed data and cannot perform that event-level masking.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!