General Flashcards

1
Q

3 Roles in Splunk Enterprise

A

Admin, Power, and User

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Admin role responsibilities

A
  • Install Apps
  • Ingest Data
  • Create Knowledge Objects for users of an app
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Power role responsibilities

A
  • Create Knowledge Objects for users of an app
  • Create real time searches
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

User role responsibilities

A
  • Only able to see their own knowledge objectives
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Source_Type

A

Classification of data

data comes into the indexer and is classified

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Default search job time limit

A

10 minutes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Shared search job time active time

A

7 days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

3 types of search modes

A

Fast, smart, verbose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Search mode differences

A

Fast - Field discovery OFF for event searches. NO Event or field data

Smart - Field discovery ON for event searches. NO Event or field data

Verbose - All event and field data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Wildcard

A

Adding a * to the end of a word like: failed*

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Boolean operations order

A
  1. NOT
  2. OR
  3. AND

() can be used to go out of order

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Splunk Search language components

A
  • Search Terms - foundation of search queries
  • Commands - tell splunk what we want to do with results liek charts or formatting
  • Functions - explain how we want to chart, compute and evaluate results
  • Arguments - variables we want to aply to the function
  • Clauses - explain how we want results grouped or defined
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Splunk search language example

A

index=network sourcetype=cisco_wsa_squid usage=Violation | stats count(usage) as Visits

Search Terms = everything till |
| = tells splunk to pass search terms to next component
Command = stats
Function = count
Argument = (usage)
Clause = as
Visits = stores the field in Visits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Most efficient way to filter results

A

time
then index, source, host, and sourcetype

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Knowledge objects categories

A

Data Interpretation - fields, field extractions, calculated fields
Data Classification - Event types, transactions
Data Normalization - Tags, field aliases
Data Models - Hierarchically structed datasets
Data Enrichment - Lookups, workflow actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Reports

A

A way to share a search

17
Q

In the Fields sidebar, Interesting Fields occur in at least ________ of resulting events.

A

20%

18
Q

Which alert action allows you to send a message to an external chat room?

A

Webhook

19
Q

Choropleth Maps

A

Need a .kmz (Keyhole markup language files)