A Universal Forwarder has the following active stanza in inputs . conf:
[monitor: //var/log]
disabled = O
host = 460352847
An event from this input has a timestamp of 10:55. What timezone will Splunk add to the event as part of indexing?
The correct answer is D. The timezone of the forwarder will be added to the event as part of indexing.
Use the time zone specified in raw event data (for example, PST, -0800), if present.
Use the TZ attribute set in props.conf, if the event matches the host, source, or source type that the stanza specifies.
If the forwarder and the receiving indexer are version 6.0 or higher, use the time zone that the forwarder provides.
Use the time zone of the host that indexes the event.
The other options are incorrect because:
Aileen
13 days agoRene
13 days agoGerald
14 days agoIzetta
17 days agoNieves
20 days agoVerdell
3 days agoBulah
8 days agoAleta
22 days agoJeanice
22 days agoToi
8 days agoWhitley
10 days agoEarleen
15 days ago