SPLK-1005 Forwarder Practice Questions
The free SPLK-1005: Splunk Cloud Certified Admin questions that deal with forwarder, with answers and explanations. The full bank and the timed practice test cover every topic the exam asks about.
Question #5
Which feature allows a heavy forwarder to route data to different indexers based on criteria such as source, sourcetype, or host?
Correct answer: B
Explanation
A heavy forwarder parses events and can apply filtering rules in props and transforms, sending selected data to specific indexer groups by host, source, or sourcetype. Cloning copies data to more destinations, while sampling and masking change volume or content.
Question #7
Which type of forwarder is a full Splunk Enterprise instance that can run apps and add-ons?
Correct answer: B
Explanation
A heavy forwarder is a full Splunk Enterprise instance that can run apps and add-ons and parse data before forwarding. A universal forwarder cannot run most apps, and a search head does not forward data.
Continue with SPLK-1005: Splunk Cloud Certified Admin
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in SPLK-1005: Splunk Cloud Certified Admin, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
All SPLK-1005: Splunk Cloud Certified Admin practice questions →
