Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.
This is a tricky question, because both HF and UF require a license, but the question asks which require a Forwarder License.
The HF uses a Enterprise License to be able to parse or index data.
The UF comes with a built-in license, but it is a license for forwarding.
So when they ask which component requires a Forwarder License, it's the UF
Correct answer is D.
I think D too because https://docs.splunk.com/Documentation/Splunk/8.0.1/Admin/Distdeploylicenses
"***Universal forwarders only need a Forwarder license.***
If a heavy forwarder is performing additional functions such as indexing data or managing searches, it requires access to an Enterprise license."
D is the correct answer.
https://docs.splunk.com/Documentation/Splunk/8.0.1/Admin/Distdeploylicenses
"***Universal forwarders only need a Forwarder license.***
This question is worded wrong. It should be asking which forwarding component requires it's own licence. The answer then would be D UF. The HF uses pool licence (ie enterprise licence). This question is also covered in Splunk Architect.
I would go D UF
It should be B as
• Forwarder license
– Sets the server up as a heavy forwarder
– Applies to non-indexing forwarders
– Allows authentication, but no indexing
UF is the answer. refer to this:
https://docs.splunk.com/Splexicon:Forwardinglicense
The universal forwarder package includes its own license. The license is enabled or applied automatically. This license allows forwarding but not indexing of unlimited data, and also enables security on the forwarder so that users must supply a user name and password to access it.
The heavy forwarder should have access to an Enterprise license stack if you plan to perform indexing on the forwarder or to enable authentication on the forwarder.
The light forwarder uses the same license as the universal forwarder. The light forwarder has been deprecated in Splunk Enterprise 6.2.0.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
BMO
Highly Voted 2 years, 10 months agotjwe
2 years, 4 months agodpharker
Highly Voted 3 years, 6 months agohappy_and_lucky
3 years, 2 months agoallahsal
Most Recent 4 weeks, 1 day agoallahsal
4 weeks agoallahsal
4 weeks, 1 day agoallahsal
4 weeks, 1 day agoVidomina
4 weeks, 1 day agobobixaka
4 months, 3 weeks agoemlch
1 year, 6 months agoMxQ3
1 year, 8 months agoApis
2 years, 2 months agogabo1969
2 years, 3 months agoinwigboji
2 years, 5 months agonot_another_user_007
2 years, 6 months agoloky0
2 years, 7 months agogsplunker
3 years, 1 month agoamsinha
3 years, 1 month agosargeholik
3 years, 2 months ago