Splunk Enterprise Certified Architect — Question 31

When would a Heavy Forwarder be needed instead of a Universal Forwarder?

Answer options

Correct answer: C

Explanation

A Heavy Forwarder is used to process and mask event data, which is necessary in this scenario to ensure sensitive information is not forwarded to indexers. The other options do not require the additional processing capabilities of a Heavy Forwarder, as a Universal Forwarder can handle TCP forwarding, routing to indexers, and changing host names without needing the same level of data handling.