Deploying Splunk Flashcards

1
Q

What is considered as a ‘Splunk Validated Architecture’ (SVAs) ?

A

Splunk Validated Architectures (SVAs) are proven reference architectures for stable, efficient, and repeatable Splunk deployments

SVAs offer topology options that consider a wide array of organizational requirements, so you can easily understand and find a topology that is right for your requirements

It does not contain implementation choices (baremetal, virtual etc), nor deployment sizing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Why an intermediate forwarder should be avoided and only used in specific cases?

A

1) A large data stream from many endpoints is funneled through a single pipe that exhausts your system and network resources.
2) Limited failover targets for the endpoints in case of IFfailure (your outage risk is reverse proportional to the number of IFs)
3) Small number of indexers are served at any given point in time. Searches over short time periods will not benefit from parallelization as much as they could otherwise.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why you should use an odd number when you deploy a SHC?

A

SHC captain election is peformed using a majority-based protocol. An odd number of nodes ensures that a SHC can never be split into even numbers of nodes during network failures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Explain what the category M14 means?

A
  • Multi-Site Indexer Cluster

* Multi-Site SearchHead Cluster and add. SearchHead Cluster for ES (contained within a site)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Explain what the category C13 means?

A
  • Single-Site Indexer Cluster

* Single-Site SearchHead Cluster with a dedicated SearchHead Cluster for ES

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Explain what the category M12 means?

A
  • Multi-Site Indexer Cluster

* Multiple SearchHeads (non-clustered) and a dedicated single SearchHead for ES

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How can you easily check if the network latency for multi-site indexer is within the recommendations of <100ms ?

A

Simply do a long-term (which needs to cover peak business hours) ping from site A indexer to site B indexer. You can output the ping data into file and index it via oneshot to analyze it (not in production environment)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the difference between category M13 and M14 in terms of SearchHead clustering?

A

In category M13, the SHCs are standalone and the search artifacts are not replicated between the sites.

M14 is consideres as the most complex implementation, it contains a streched SearchHead Cluster over all sites.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

If a device logs only via API and software can not be installed, which input technology would be best practise to use?

A

Splunk HEC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a DCN?

A

A data collection node (eg Heavy Forwarder)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the meaning of DR?

A

Set of processes necessary to ensure recovery of service after a disaster

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How can a manual DR be archieved in Splunk?

A

Backup of
> Splunk configurations (/etc/*)
> Indexes (introduce a specific backup concept for clustered indexer)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How can an automatic DR be implemented in Splunk?

A

Through introducing multiple sites (if one site goes down, the other site still have all data available (only if the replication factor is set accordingly))

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the meaning of HA?

A

A design methodology whereby a system is continuously operational, bounded by a set of predetermined tolerances

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Why an all-in-one Splunk instance could grow to a distributed environment?

A
  • End of testing
  • End of the PoC
  • System reached its search and index limitations
  • Introduction of failover strategies
  • Dedicated teams for dedicated SearchHeads
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

In which specific cases an intermediate forwarder makes sense?

A

Specific cases where an intermediate forwarder may makes sense:

Sensitive data needs to be obfuscated/removed before sending across the network to indexers. An example is when you must use a public network

Strict security policies do not allow for direct connections between endpoints and indexers such as multi-zone networks or cloud-based indexers

Bandwidth constraints between endpoints and indexers requiring a significant subset of events to be filtered

Data routing reasons