SPLK-2002 Exam QuestionsBrowse all questions from this exam

SPLK-2002 Exam - Question 77


Which of the following options can improve reliability of syslog delivery to Splunk? (Select all that apply.)

Show Answer
Correct Answer: AD

To improve the reliability of syslog delivery to Splunk, using TCP for syslog is beneficial. TCP is a connection-oriented protocol that ensures data delivery, which can significantly enhance reliability compared to UDP. Additionally, implementing one or more syslog servers to persist data and using a Universal Forwarder to send this data to Splunk indexers is another effective approach. This method helps in capturing and forwarding logs even during interruptions or Splunk process downtimes.

Discussion

7 comments
Sign in to comment
sadhkaOptions: AD
Sep 11, 2020

My answer is A and D

M_K_SOptions: AC
Oct 30, 2020

Mine is A,C,D

manu78Options: AD
Apr 19, 2021

A and D are correct

AnaBeeOptions: AD
Dec 27, 2021

pg 129 | Archietecting & pg 71 | Troubleshooting

qtygbapjpesdayazko
Apr 18, 2023

wildcards are not efficient

wirix25718
Apr 19, 2023

Is it not top

b5white
Aug 4, 2023

A Splunk instance can listen on any port for incoming syslog messages. While this is easy to configure, it’s not considered best practice for getting syslog messages into Splunk. If the splunkd process stops, all syslog messages sent during the downtime would be lost. -- The Complete Guide to Using Syslog with Splunk https://kinneygroup.com/blog/splunk-syslog/

b5white
Aug 4, 2023

So C D