nerdexam
Splunk

SPLK-1003 · Question #128

Which forwarder is recommended by Splunk to use in a production environment?

The correct answer is D. Universal forwarder. Splunk explicitly recommends the Universal Forwarder (UF) for production deployments. It is a dedicated, lightweight agent with a small footprint that is purpose-built for securely collecting and forwarding data to indexers or heavy forwarders. It does not run a full Splunk…

Splunk Forwarding

Question

Which forwarder is recommended by Splunk to use in a production environment?

Options

  • AHeavy forwarder
  • BSSL forwarder
  • CLightweight forwarder
  • DUniversal forwarder

How the community answered

(50 responses)
  • A
    8% (4)
  • B
    4% (2)
  • C
    2% (1)
  • D
    86% (43)

Explanation

Splunk explicitly recommends the Universal Forwarder (UF) for production deployments. It is a dedicated, lightweight agent with a small footprint that is purpose-built for securely collecting and forwarding data to indexers or heavy forwarders. It does not run a full Splunk instance, which reduces resource consumption on the source machine. The Heavy Forwarder (A) is a full Splunk installation used only when advanced processing (parsing, filtering, routing) must happen before data reaches the indexer-it is not the default recommendation. 'SSL forwarder' (B) is not a distinct Splunk product; SSL is a transport option. The Lightweight Forwarder (C) is a deprecated legacy product replaced by the Universal Forwarder.

Topics

#Universal forwarder#Forwarder types#Production environment#Best practices

Community Discussion

No community discussion yet for this question.

Full SPLK-1003 Practice