The guidance Splunk gives for estimating size on for syslog data is 50% of original data size.
How does this divide between files in the index?
A . rawdata is: 10%, tsidx is: 40%
B . rawdata is: 15%, tsidx is: 35%
C . rawdata is: 35%, tsidx is: 15%
D . rawdata is: 40%, tsidx is: 10%
Answer: B
Explanation:
Reference: https://answers.splunk.com/answers/147951/what-is-the-compression-ratio-of-raw-data-insplunk.html
Latest SPLK-2002 Dumps Valid Version with 90 Q&As
Latest And Valid Q&A | Instant Download | Once Fail, Full Refund