Splunk Core Certified User — Question 41
We should use heavy forwarder for sending event-based data to Indexers.
Answer options
- A. False
- B. True
Correct answer: B
Explanation
The correct answer is True because a heavy forwarder is designed to collect and forward event-based data efficiently to Indexers. Using a heavy forwarder allows for preprocessing of the data, which is essential in optimizing data ingestion, unlike a light forwarder which has limited capabilities.