Agreed D. Quoting the Splunk reference URL https://docs.splunk.com/Documentation/Splunk/latest/Deploy/Datapipeline
"The data pipeline segments in depth. INPUT - In the input segment, Splunk software consumes data. It acquires the raw data stream from its source, breaks it into 64K blocks, and annotates each block with some metadata keys. The keys can also include values that are used internally, such as the character encoding of the data stream, and values that control later processing of the data, such as the index into which the events should be stored. PARSING Annotating individual events with metadata copied from the source-wide keys. Transforming event data and metadata according to regex transform rules."
Answer D
UF inside props.conf limited parsing such as character encoding, refine metadata, event breaks
indexer inside props.conf refines metadata at event level, event break, time extraction, tx, data transformation
Confirmed D - "During the input phase, Splunk sets all input data to UTF-8 encoding by default – Can be overridden, if needed, by setting the CHARSETattribute"
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
islamjy
Highly Voted 2 years, 12 months agoucsdmiami2020
2 years, 10 months agoFrozenYeti
Most Recent 4 weeks, 1 day agoHNaka
7 months agosaurabhsood
2 years, 1 month agoSeba0297
2 years, 3 months agoBlueRoselia
2 years, 5 months agoFe01
2 years, 7 months agoSalman23
2 years, 11 months agofuriousjase
2 years, 11 months agokiranhar
2 years, 12 months agokiranhar
2 years, 12 months agokiranhar
3 years ago