When configuring HTTP Event Collector (HEC) input, how would one ensure the events have been indexed?
When configuring HTTP Event Collector (HEC) input, how would one ensure the events have been indexed?
A . Enable indexer acknowledgment.
B . Enable forwarder acknowledgment.
C . splunk check-integrity -index <index name>
D . index=_internal component=ACK | stats count by host
Answer: A
Explanation:
Per the provided Splunk reference URL https://docs.splunk.com/Documentation/Splunk/8.0.5/Data/AboutHECIDXAck
"While HEC has precautions in place to prevent data loss, it’s impossible to completely prevent such an occurrence, especially in the event of a network failure or hardware crash. This is where indexer acknolwedgment comes in."
Reference https://docs.splunk.com/Documentation/Splunk/8.0.5/Data/AboutHECIDXAck
Latest SPLK-1003 Dumps Valid Version with 119 Q&As
Latest And Valid Q&A | Instant Download | Once Fail, Full Refund