nerdexam
Splunk

SPLK-3003 · Question #45

A customer is having issues with truncated events greater than 64K. What configuration should be deployed to a universal forwarder (UF) to fix the issue?

The correct answer is C. EVENT_BREAKER_ENABLE and EVENT_BREAKER regular expression settings per sourcetype. https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/Resolvedataqualityissues

Data Ingestion and Configuration

Question

A customer is having issues with truncated events greater than 64K. What configuration should be deployed to a universal forwarder (UF) to fix the issue?

Options

  • ANone. Splunk default configurations will process the events as needed; the UF is not causing
  • BConfigure the best practice magic 6 or great 8 props.conf settings.
  • CEVENT_BREAKER_ENABLE and EVENT_BREAKER regular expression settings per sourcetype.
  • DGlobal EVENT_BREAKER_ENABLE and EVENT_BREAKER regular expression settings.

How the community answered

(66 responses)
  • A
    11% (7)
  • B
    3% (2)
  • C
    79% (52)
  • D
    8% (5)

Explanation

https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/Resolvedataqualityissues

Topics

#EVENT_BREAKER#event truncation#universal forwarder#props.conf

Community Discussion

No community discussion yet for this question.

Full SPLK-3003 Practice