SPLK-1003 · Question #128
Which forwarder is recommended by Splunk to use in a production environment?
The correct answer is D. Universal forwarder. Splunk explicitly recommends the Universal Forwarder (UF) for production deployments. It is a dedicated, lightweight agent with a small footprint that is purpose-built for securely collecting and forwarding data to indexers or heavy forwarders. It does not run a full Splunk…
Question
Which forwarder is recommended by Splunk to use in a production environment?
Options
- AHeavy forwarder
- BSSL forwarder
- CLightweight forwarder
- DUniversal forwarder
How the community answered
(50 responses)- A8% (4)
- B4% (2)
- C2% (1)
- D86% (43)
Explanation
Splunk explicitly recommends the Universal Forwarder (UF) for production deployments. It is a dedicated, lightweight agent with a small footprint that is purpose-built for securely collecting and forwarding data to indexers or heavy forwarders. It does not run a full Splunk instance, which reduces resource consumption on the source machine. The Heavy Forwarder (A) is a full Splunk installation used only when advanced processing (parsing, filtering, routing) must happen before data reaches the indexer-it is not the default recommendation. 'SSL forwarder' (B) is not a distinct Splunk product; SSL is a transport option. The Lightweight Forwarder (C) is a deprecated legacy product replaced by the Universal Forwarder.
Topics
Community Discussion
No community discussion yet for this question.