A Splunk architect has inherited the Splunk deployment at Buttercup Games and end users are complaining that the events are inconsistently formatted for a web sourcetype. Further investigation reveals that not all web logs flow through the same infrastructure: some of the data goes through heavy forwarders and some of the forwarders are managed by another department. Which of the following items might be the cause for this issue?
- The search head may have different configurations than the indexers.
- The data inputs are not properly configured across all the forwarders.
- The indexers may have different configurations than the heavy forwarders.
- The forwarders managed by the other department are an older version than the rest.
Reveal Solution
Next Question