exam questions

Exam SPLK-3003 All Questions

View all questions & answers for the SPLK-3003 exam

Exam SPLK-3003 topic 1 question 84 discussion

Actual exam question from Splunk's SPLK-3003
Question #: 84
Topic #: 1
[All SPLK-3003 Questions]

The universal forwarder (UF) should be used whenever possible, as it is smaller and more efficient. In which of the following scenarios would a heavy forwarder
(HF) be a more appropriate choice?

  • A. When a predictable version of Python is required.
  • B. When filtering 10%""15% of incoming events.
  • C. When monitoring a log file.
  • D. When running a script.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Nemo72
Highly Voted 3 years, 5 months ago
A is the correct because Use the universal forwarder whenever possible, it is smaller and more efficient. Only use a heavy forwarder when: • The UI is needed • Advanced event-level routing is needed • You are filtering more than 80% of incoming events • Anonymizing or masking data before forwarding to indexer • Predictable version of Python is needed • Required by an app/modular input (HEC, DBX, Checkpoint OPSEC LEA)
upvoted 11 times
...
bobixaka
Most Recent 1 month ago
Selected Answer: A
That's one super tricky question! In reality, B would be correct as well! You would use a Heavy Forwarder as an Intermediate Forwarder to filter out any amount of unnecessary events with REGEX filters and send them to the nullQueue. You wouldn't want to do that on the Indexers, because they are too busy anyway. I've done that and these filters consume a lot of CPU even if you want to filter out like 10-15% of the events... According to the CI Slides p.163 you can use it to filter out 80% and more, but I don't agree... Anyway, the correct answer is "A", because that's what the CI Slides PDF states on p.163...
upvoted 1 times
...
Steve2610
1 year, 8 months ago
A - Page 5
upvoted 2 times
...
Redtonyeah
2 years, 1 month ago
Selected Answer: A
A, page 163 SCI
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago