Splunk Enterprise Certified Admin SPLK-1003 Question # 28 Topic 3 Discussion

Splunk Enterprise Certified Admin SPLK-1003 Question # 28 Topic 3 Discussion

SPLK-1003 Exam Topic 3 Question 28 Discussion:
Question #: 28
Topic #: 3

The following stanzas in inputs. conf are currently being used by a deployment client:

[udp: //145.175.118.177:1001

Connection_host = dns

sourcetype = syslog

Which of the following statements is true of data that is received via this input?


A.

If Splunk is restarted, data will be queued and then sent when Splunk has restarted.


B.

Local firewall ports do not need to be opened on the deployment client since the port is defined in inputs.conf.


C.

The host value associated with data received will be the IP address that sent the data.


D.

If Splunk is restarted, data may be lost.


Get Premium SPLK-1003 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.