Okay, let me see... I remember the first step is "sort", and the last two are "standardize" and "sustain". But I'm drawing a blank on the middle steps. I'll have to make an educated guess on this one.
Didn't we practice a question about controlling work based on item status? That makes me think option 3 is also valid, so maybe 1 and 3 are right together?
This is a tricky one! I'd say the funniest answer is probably option A - 'If Splunk is restarted, data will be queued and then sent when Splunk has restarted.' That's a bit of a stretch, isn't it?
Option C sounds good to me. Since the connection_host is set to 'dns', the host value associated with the data should be the IP address that sent the data, not the Splunk server's IP.
I'm leaning towards B) Local firewall ports do not need to be opened on the deployment client since the port is defined in inputs.conf. It just makes sense to me.
I'm not sure about option B. Even though the port is defined in inputs.conf, I think you'd still need to open the firewall ports on the deployment client to allow the traffic to flow through.
Aliza
6 months agoPearly
6 months agoHildegarde
7 months agoJacqueline
7 months agoCyndy
7 months agoArmando
7 months agoKing
7 months agoThea
8 months agoApolonia
8 months agoAlisha
8 months agoLenora
8 months agoCordelia
8 months agoRodolfo
1 year agoRene
11 months agoRonny
11 months agoAlexia
11 months agoJanae
1 year agoPeggie
1 year agoFrancene
11 months agoLeontine
11 months agoRaymon
11 months agoMargarita
12 months agoHyman
1 year agoEden
1 year agoAdell
1 year agoAvery
1 year agoLaticia
1 year agoLettie
1 year agoNoel
1 year agoElizabeth
1 year agoAnnelle
1 year agoIvan
1 year agoMargarita
1 year agoNikita
1 year agoRaina
1 year agoGlenn
1 year ago