Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Splunk Exam SPLK-1003 Topic 10 Question 71 Discussion

Actual exam question for Splunk's SPLK-1003 exam
Question #: 71
Topic #: 10
[All SPLK-1003 Questions]

The following stanzas in inputs. conf are currently being used by a deployment client:

[udp: //145.175.118.177:1001

Connection_host = dns

sourcetype = syslog

Which of the following statements is true of data that is received via this input?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

Eden
2 days ago
I disagree, I believe the correct answer is D) If Splunk is restarted, data may be lost because it's not guaranteed to be queued.
upvoted 0 times
...
Adell
4 days ago
I think the answer is A) If Splunk is restarted, data will be queued and then sent when Splunk has restarted.
upvoted 0 times
...
Avery
5 days ago
I'm leaning towards B. Local firewall ports don't need to be opened.
upvoted 0 times
...
Laticia
6 days ago
I'm not sure about option B. Even though the port is defined in inputs.conf, I think you'd still need to open the firewall ports on the deployment client to allow the traffic to flow through.
upvoted 0 times
...
Nikita
9 days ago
Hmm, I think option D is the correct answer here. If Splunk is restarted, any data that hasn't been fully processed yet could potentially be lost.
upvoted 0 times
...
Raina
11 days ago
I disagree, I believe the answer is D. Data may be lost if Splunk is restarted.
upvoted 0 times
...
Glenn
13 days ago
I think the answer is A. Data will be queued and sent after restart.
upvoted 0 times
...

Save Cancel