Splunk Core Certified User — Question 41

We should use heavy forwarder for sending event-based data to Indexers.

Answer options

Correct answer: B

Explanation

The correct answer is True because a heavy forwarder is designed to collect and forward event-based data efficiently to Indexers. Using a heavy forwarder allows for preprocessing of the data, which is essential in optimizing data ingestion, unlike a light forwarder which has limited capabilities.