B and D both: compressed=true This tells the forwarder to compress the data before it forwards the data to receiving indexers in the target groups. If you set compressed to "false", the forwarder sends raw data.
Splunk doc: https://docs.splunk.com/Documentation/Forwarder/8.1.1/Forwarder/Configureforwardingwithoutputs.conf#:~:text=compressed%3Dtrue%20This%20tells%20the,the%20forwarder%20sends%20raw%20data.
I think C is also correct.
https://docs.splunk.com/Documentation/Splunk/latest/Data/Anonymizedata
"To anonymize data with Splunk Enterprise, you must configure a Splunk Enterprise instance as a heavy forwarder and anonymize the incoming data with that instance before sending it to Splunk Enterprise."
UF has the following capabilities:
- Index ack* (useACK=true in outputs.conf)
- Send data over HTTP
- Compressing the feed (compressed = true on both input.conf (indexer) and outputs.conf (uf))
- Securing the feed with SSL
So, D and B
C. that would be a HF
A. not sure if Forwarders in general can send alerts
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Ashton_98
Highly Voted 4 years, 1 month agoPrincee
Highly Voted 3 years, 10 months agogatundu_
Most Recent 3 months agonewrose
4 months, 2 weeks agodohatelo
8 months, 2 weeks agobobixaka
1 year, 1 month agoIbisc
1 year, 6 months agoMntman77
1 year, 5 months agoharrytbb
1 year, 10 months agoemlch
2 years, 3 months agoemlch
2 years, 3 months agoAilen_Man
2 years, 7 months agoMarco63
2 years, 8 months agoRedYeti
2 years, 9 months agoApis
2 years, 11 months agoBMO
3 years, 6 months agoZeusP
3 years, 7 months ago