Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Splunk SPLK-1004 Exam - Topic 9 Question 55 Discussion

Why is the transaction command slow in large Splunk deployments?
C) It forces all event data to be returned to the search head.
A) It forces the search to run in fast mode.
B) The transaction runs on each indexer in parallel.
D) The transaction runs a hidden eval to format fields.

Splunk SPLK-1004 Exam - Topic 9 Question 55 Discussion

Actual exam question for Splunk's SPLK-1004 exam
Question #: 55
Topic #: 9
[All SPLK-1004 Questions]

Why is the transaction command slow in large Splunk deployments?

Show Suggested Answer Hide Answer
Suggested Answer: C

The transaction command can be slow in large deployments because it requires all event data relevant to the transaction to be returned to the search head, which can be resource-intensive.


Contribute your Thoughts:

0/2000 characters
Audrie
4 days ago
I feel like the hidden eval part could be a factor too, but I can't recall if that's specifically mentioned in the context of performance issues.
upvoted 0 times
...
Jaclyn
9 days ago
I think I saw a practice question about how the transaction command returns all event data to the search head, which might be why it's slow.
upvoted 0 times
...
Iraida
14 days ago
I remember discussing how the transaction command can be resource-intensive, but I'm not sure if it's because it runs on each indexer or something else.
upvoted 0 times
...

Save Cancel