nerdexam
Splunk

SPLK-1003 · Question #91

When running a real-time search, search results are pulled from which Splunk component?

The correct answer is D. Search peers. Using the Splunk reference URL https://docs.splunk.com/Splexicon:Searchpeer "search peer is a splunk platform instance that responds to search requests from a search head. The term "search peer" is usally synonymous with the indexer role in a distributed search topology…

Distributed Search

Question

When running a real-time search, search results are pulled from which Splunk component?

Options

  • AHeavy forwarders and search peers
  • BHeavy forwarders
  • CSearch heads
  • DSearch peers

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    3% (1)
  • D
    87% (27)

Explanation

Using the Splunk reference URL https://docs.splunk.com/Splexicon:Searchpeer "search peer is a splunk platform instance that responds to search requests from a search head. The term "search peer" is usally synonymous with the indexer role in a distributed search topology. However, other instance types also have access to indexed data, particularly internal diagnostic data, and thus function as search peers when they respond to search requests for that

Topics

#real-time search#distributed search#search peers#search architecture

Community Discussion

No community discussion yet for this question.

Full SPLK-1003 Practice