SPLK-1003 · Question #141
The following stanzas in inputs. conf are currently being used by a deployment client: [udp: //145.175.118.177:1001 Connection_host = dns sourcetype = syslog Which of the following statements is…
The correct answer is D. If Splunk is restarted, data may be lost. UDP (User Datagram Protocol) is a connectionless, fire-and-forget protocol with no built-in acknowledgment, buffering, or retransmission. If Splunk stops or restarts while receiving UDP data, any packets in transit during that window are simply dropped - there is no queue to…
Question
The following stanzas in inputs. conf are currently being used by a deployment client:
[udp: //145.175.118.177:1001 Connection_host = dns sourcetype = syslog Which of the following statements is true of data that is received via this input?
Options
- AIf Splunk is restarted, data will be queued and then sent when Splunk has restarted.
- BLocal firewall ports do not need to be opened on the deployment client since the port is defined in
- CThe host value associated with data received will be the IP address that sent the data.
- DIf Splunk is restarted, data may be lost.
How the community answered
(38 responses)- A8% (3)
- B5% (2)
- C16% (6)
- D71% (27)
Explanation
UDP (User Datagram Protocol) is a connectionless, fire-and-forget protocol with no built-in acknowledgment, buffering, or retransmission. If Splunk stops or restarts while receiving UDP data, any packets in transit during that window are simply dropped - there is no queue to hold them. This is a fundamental characteristic of UDP vs. TCP. TCP-based inputs (like tcp://) can buffer and resume. Additionally, the 'connection_host=dns' setting means the host field is derived from the DNS name of the sender's IP - not the raw IP address - making option C incorrect.
Topics
Community Discussion
No community discussion yet for this question.