ExamGecko
Question list
Search
Search

Question 154 - SPLK-1003 discussion

Report
Export

The following stanzas in inputs. conf are currently being used by a deployment client:

[udp: //145.175.118.177:1001

Connection_host = dns

sourcetype = syslog

Which of the following statements is true of data that is received via this input?

A.
If Splunk is restarted, data will be queued and then sent when Splunk has restarted.
Answers
A.
If Splunk is restarted, data will be queued and then sent when Splunk has restarted.
B.
Local firewall ports do not need to be opened on the deployment client since the port is defined in inputs.conf.
Answers
B.
Local firewall ports do not need to be opened on the deployment client since the port is defined in inputs.conf.
C.
The host value associated with data received will be the IP address that sent the data.
Answers
C.
The host value associated with data received will be the IP address that sent the data.
D.
If Splunk is restarted, data may be lost.
Answers
D.
If Splunk is restarted, data may be lost.
Suggested answer: D

Explanation:

This is because the input type is UDP, which is an unreliable protocol that does not guarantee delivery, order, or integrity of the data packets. UDP does not have any mechanism to resend or acknowledge the data packets, so if Splunk is restarted, any data that was in transit or in the buffer may be dropped and not indexed.

asked 23/09/2024
Shauqi Naufaldy
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first