nerdexam
Amazon

DEA-C01 · Question #100

A company plans to provision a log delivery stream within a VPC. The company configured the VPC flow logs to publish to Amazon CloudWatch Logs. The company needs to send the flow logs to Splunk in…

The correct answer is B. Create an Amazon Kinesis Data Firehose delivery stream to use Splunk as the destination. Kinesis Data Firehose has built-in support for Splunk as a destination, making the integration straightforward. Using a CloudWatch Logs subscription filter directly to Firehose simplifies the data flow, eliminating the need for additional Lambda functions or custom integrations.

Data Ingestion and Transformation

Question

A company plans to provision a log delivery stream within a VPC. The company configured the VPC flow logs to publish to Amazon CloudWatch Logs. The company needs to send the flow logs to Splunk in near real time for further analysis. Which solution will meet these requirements with the LEAST operational overhead?

Options

  • AConfigure an Amazon Kinesis Data Streams data stream to use Splunk as the destination. Create
  • BCreate an Amazon Kinesis Data Firehose delivery stream to use Splunk as the destination.
  • CCreate an Amazon Kinesis Data Firehose delivery stream to use Splunk as the destination.
  • DConfigure an Amazon Kinesis Data Streams data stream to use Splunk as the destination. Create

How the community answered

(49 responses)
  • A
    4% (2)
  • B
    78% (38)
  • C
    12% (6)
  • D
    6% (3)

Explanation

Kinesis Data Firehose has built-in support for Splunk as a destination, making the integration straightforward. Using a CloudWatch Logs subscription filter directly to Firehose simplifies the data flow, eliminating the need for additional Lambda functions or custom integrations.

Topics

#Kinesis Data Firehose#CloudWatch Logs#Log Streaming#Splunk Integration

Community Discussion

No community discussion yet for this question.

Full DEA-C01 Practice