Which Splunk configuration ensures events are parsed and indexed only once for optimal storage?

Which Splunk configuration ensures events are parsed and indexed only once for optimal storage?
A . Summary indexing
B . Universal forwarder
C . Index time transformations
D . Search head clustering

Answer: C

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments