Admin Guide 9.0.4 Flashcards

1
Q

Best practice for optimal performance - dedicated machines

A

Adding more physical machines dedicated to Splunk Enterprise translates into better performance than having more resources in a single machine.
Where possible, split up your indexing and searching activities across a number of machines, and only run one Splunk Enterprise component on each machine.
Performance is reduced when you run Splunk Enterprise on machines that share resources with other services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Best practice for optimal performance - antivirus

A

If you use anti-virus programs on the servers running Splunk Enterprise, make sure that all Splunk software directories and programs are excluded from on-access file scans.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Best practice for optimal performance - indexes

A

Use multiple indexes, where possible.
Sending all data to one index can cause I/O bottlenecks on your system and complicate retention calculations and access controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Best practice for optimal performance - disk/volume considerations

A

Don’t store your indexes on the same physical disk or volume as the operating system.
The disk that holds your operating system or its swap file is not a recommended place for Splunk Enterprise data storage.
Put your indexes on other disks or volumes mounted on the machine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Best practice for optimal performance - buckets location

A

Don’t store the hot and warm buckets of your indexes on network volumes
Always use fast, local disk for the index hot and warm buckets.
You can specify network shares for the cold and frozen buckets of an index using Distributed File System (DFS) volumes or Network File System (NFS) mounts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Best practice for optimal performance - minimal disk space

A

The volume or mount that contains your indexes must have approximately 5 gigabytes of free disk space by default, or indexing will stop.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Splunk web default port

A

8000

http://localhost:8000

http://<hostname>:8000</hostname>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Configuration files

A

These files are located under your Splunk installation directory (usually referred to in the documentation as $SPLUNK_HOME) under /etc/system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

preferred Splunk Enterprise component to integrate into a Windows system image

A

universal forwarder is designed to share resources on computers that perform other roles, and does much of the work that an indexer can, at much less cost.
You can also modify the forwarder’s configuration using the deployment server or an enterprise-wide configuration manager with no need to use Splunk Web to make changes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

access Splunk Free from a remote browser

A

You cannot access Splunk Free from a remote browser until you have edited $SPLUNK_HOME/etc/local/server.conf and set allowRemoteLogin to Always.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly