Okay, let me see... I remember the first step is "sort", and the last two are "standardize" and "sustain". But I'm drawing a blank on the middle steps. I'll have to make an educated guess on this one.
Didn't we practice a question about controlling work based on item status? That makes me think option 3 is also valid, so maybe 1 and 3 are right together?
This is a tricky one! I'd say the funniest answer is probably option A - 'If Splunk is restarted, data will be queued and then sent when Splunk has restarted.' That's a bit of a stretch, isn't it?
Option C sounds good to me. Since the connection_host is set to 'dns', the host value associated with the data should be the IP address that sent the data, not the Splunk server's IP.
I'm leaning towards B) Local firewall ports do not need to be opened on the deployment client since the port is defined in inputs.conf. It just makes sense to me.
I'm not sure about option B. Even though the port is defined in inputs.conf, I think you'd still need to open the firewall ports on the deployment client to allow the traffic to flow through.
Aliza
5 months agoPearly
5 months agoHildegarde
5 months agoJacqueline
5 months agoCyndy
6 months agoArmando
6 months agoKing
6 months agoThea
6 months agoApolonia
6 months agoAlisha
6 months agoLenora
6 months agoCordelia
6 months agoRodolfo
11 months agoRene
9 months agoRonny
10 months agoAlexia
10 months agoJanae
11 months agoPeggie
11 months agoFrancene
9 months agoLeontine
9 months agoRaymon
10 months agoMargarita
10 months agoHyman
12 months agoEden
12 months agoAdell
12 months agoAvery
12 months agoLaticia
1 year agoLettie
11 months agoNoel
11 months agoElizabeth
11 months agoAnnelle
11 months agoIvan
11 months agoMargarita
12 months agoNikita
1 year agoRaina
1 year agoGlenn
1 year ago