Enterprise only content Flashcards
Splunk licensing is based …
on the amount of data indexed.
The daily license quote includes the full size of data flowing through the ___, but not the disk storage.
parsing pipeline
Replicated data, summary indexes, internal logs, and metadata ___ count towards license quota.
does not
What are the Splunk license options?
Enterprise Free Trial Splunk for industrial IoT license Forward Dev/test license
Enterprise
o Can be bought for any indexing volume
o Enables all Splunk features including clustering and distributed search
o No enforcement. Users can still search after license violation
o Licenses can be stacked
Free
o Includes 500mb/day indexing for life
o Disabled features include clustering, authentication, distributed search, alerting and deployment management
Trial
o Full Splunk features for 60 days
o After 60 says it automatically becomes free license
o Max 500mb a day
o Sales Trial license can be provided for customised license
Splunk for industrial IoT
o Not stackable
o Access to Splunk enterprise and a select premium Splunk apps
Forward
o Allows forwarding of unlimited data
o Cannot be used for indexing
o No need to purchase separately
o Universal forwards automatically apply forwarder license
o Heavy forwarder must be converted to Forwarder License group
Dev/Test
o For running Splunk in Non Prod environments
o Cannot be used in distributed environment
o Not stackable
o Can be used for Splunk App development
What are the license warnings and violations?
- Exceeding daily volume quota results in a warning
- 5 or more warnings in a 30 day rolling period is a violation
- Searching is not disabled in violation period
- Alert logged in Messages on any Splunk Web pages
How do you monitor for license warnings?
- Monitoring console
- Licensing page in Splunk web
- Usage report in Splunk Web
How do you handle license violations?
- Review heavy hitters (usage report) and adjust intake
- The daily limit resets at midnight
- Buy more licenses
How is a search performed?
- During indexing, Splunk indexers convert the machine data stream into searchable events which are stored in indexes
- Indexes contain compressed raw data (journal.gz) and time-series index files (TSIDX)
- Indexes store data in time-oriented buckets (hot, warm, cold and frozen)
- Indexers perform the search and return the results
- Search results and meta data are stored as search artifacts until the search job expires
How does Splunk retrieve data?
- Timeframe – identify data buckets based on time range
* Bloom filter – calculate bloom filter on base search and compare against buckets bloom filter