This is a tricky one! I'd say the funniest answer is probably option A - 'If Splunk is restarted, data will be queued and then sent when Splunk has restarted.' That's a bit of a stretch, isn't it?
Option C sounds good to me. Since the connection_host is set to 'dns', the host value associated with the data should be the IP address that sent the data, not the Splunk server's IP.
I'm leaning towards B) Local firewall ports do not need to be opened on the deployment client since the port is defined in inputs.conf. It just makes sense to me.
I'm not sure about option B. Even though the port is defined in inputs.conf, I think you'd still need to open the firewall ports on the deployment client to allow the traffic to flow through.
Rodolfo
10 days agoJanae
13 days agoPeggie
14 days agoHyman
2 months agoEden
2 months agoAdell
2 months agoAvery
2 months agoLaticia
2 months agoLettie
16 days agoNoel
24 days agoElizabeth
29 days agoAnnelle
30 days agoIvan
1 months agoMargarita
1 months agoNikita
2 months agoRaina
2 months agoGlenn
2 months ago