An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data is 300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the index?
A new forwarder has been installed with a manually created deploymentclient.conf. What is the next step to enable the communication between the forwarder and the deployment server?
Load balancing on a Universal Forwarder is not scaling correctly. The forwarder's outputs. and the tcpoutstanza are setup correctly. What else could be the cause of this scaling issue? (select all that apply)