Splunk
SPLK-3003 · Question #34
As a best practice which of the following should be used to ingest data on clustered indexers?
The correct answer is D. splunktcp, splunktcp-ssl, HTTP Event Collector (HEC). https://docs.splunk.com/Documentation/Splunk/9.2.0/Indexer/Indexerclusterinputs
Data Ingestion and Configuration
Question
As a best practice which of the following should be used to ingest data on clustered indexers?
Options
- AMonitoring (via a process), collecting data (modular inputs) from remote systems/applications
- BModular inputs, HTTP Event Collector (HEC), inputs.conf monitor stanza
- CActively listening on ports, monitoring (via a process), collecting data from remote
- Dsplunktcp, splunktcp-ssl, HTTP Event Collector (HEC)
How the community answered
(47 responses)- A2% (1)
- B11% (5)
- C4% (2)
- D83% (39)
Explanation
https://docs.splunk.com/Documentation/Splunk/9.2.0/Indexer/Indexerclusterinputs
Topics
#clustered indexers#data ingestion#splunktcp#HEC
Community Discussion
No community discussion yet for this question.