Splunk SPLK-3003 Exam - Topic 1 Question 17 Discussion
A customer is having issues with truncated events greater than 64K. What configuration should be deployed to a universal forwarder (UF) to fix the issue?
C) EVENT_BREAKER_ENABLE and EVENT_BREAKER regular expression settings per sourcetype.
A) None. Splunk default configurations will process the events as needed; the UF is not causing truncation.
B) Configure the best practice magic 6 or great 8 props.conf settings.
D) Global EVENT_BREAKER_ENABLE and EVENT_BREAKER regular expression settings.
Chauncey
8 months agoGlory
8 months agoJeannetta
9 months agoGracia
9 months agoGwenn
9 months agoTiera
9 months agoDeonna
9 months agoLashawna
9 months agoGertude
9 months agoJohanna
9 months agoRebbeca
9 months agoSarah
9 months agoHershel
10 months ago