nerdexam
Splunk

SPLK-1003 · Question #141

The following stanzas in inputs. conf are currently being used by a deployment client: [udp: //145.175.118.177:1001 Connection_host = dns sourcetype = syslog Which of the following statements is…

The correct answer is D. If Splunk is restarted, data may be lost. UDP (User Datagram Protocol) is a connectionless, fire-and-forget protocol with no built-in acknowledgment, buffering, or retransmission. If Splunk stops or restarts while receiving UDP data, any packets in transit during that window are simply dropped - there is no queue to…

Splunk Forwarding

Question

The following stanzas in inputs. conf are currently being used by a deployment client:

[udp: //145.175.118.177:1001 Connection_host = dns sourcetype = syslog Which of the following statements is true of data that is received via this input?

Options

  • AIf Splunk is restarted, data will be queued and then sent when Splunk has restarted.
  • BLocal firewall ports do not need to be opened on the deployment client since the port is defined in
  • CThe host value associated with data received will be the IP address that sent the data.
  • DIf Splunk is restarted, data may be lost.

How the community answered

(38 responses)
  • A
    8% (3)
  • B
    5% (2)
  • C
    16% (6)
  • D
    71% (27)

Explanation

UDP (User Datagram Protocol) is a connectionless, fire-and-forget protocol with no built-in acknowledgment, buffering, or retransmission. If Splunk stops or restarts while receiving UDP data, any packets in transit during that window are simply dropped - there is no queue to hold them. This is a fundamental characteristic of UDP vs. TCP. TCP-based inputs (like tcp://) can buffer and resume. Additionally, the 'connection_host=dns' setting means the host field is derived from the DNS name of the sender's IP - not the raw IP address - making option C incorrect.

Topics

#UDP inputs#Data reliability#inputs.conf#Data loss

Community Discussion

No community discussion yet for this question.

Full SPLK-1003 Practice