Installation and Configuration Flashcards
How does ES know local customer domain names so it can detect internal vs external emails?
The Corporate Web and Email Domain Lookups are edited during initial configuration.
Where would you navigate to edit Domain Tables?
- Configure>Content>Content Management
- Select Type:Managed Lookup
- Edit any of the Domain lookups: Corporate Web Domains, Corporate Email Domains, Cloud Domains (external vendor sites)
What are the default ports that must be configured for Splunk ES to function?
- SplunkWeb (8000)
- Splunk Management (8089)
- KV Store (8191)
Which tool is used to update indexers in ES?
Splunk_TA_ForIndexers.spl
Which of the following is accurate regarding the input phase?
- Applies event-level transformations
- Fine-tunes metadata
- Performs character encoding
- Breaks data into events with timestamps
Performs character encoding.
A site has a single existing search head which hosts a mix of both CIM and non-CIM compliant applications. All of the applications are mission-critical. The customer wants to carefully control cost, but wants good ES performance. What is the best practice for installing ES?
Add a new search head and install ES on it.
ES apps and add-ons from $SPLUNK_HOME/etc/apps should be copied from the staging instance to what location on the cluster deployer instance?
$SPLUNK_HOME/etc/shcluster/apps
After installing Enterprise Security, the distributed configuration management tool can be used to create which app to configure indexers?
Splunk_TA_ForIndexers.spl
Installation Checklist
- Confirm the environment meets minimum system requirements for Splunk Enterprise and ES.
- Increase the Splunk Web upload size limit in web.conf
- Install ES on the search head
- Install any required TAs
- Create Splunk_TA_ForIndexers to deploy to indexers.
- Deploy input-time technical add-ons to forwarders.
ES needs to be installed on a search head with _____.
Only default built-in and CIM-compliant apps.
What are the search head requirements for installing ES?
- A dedicated server or cluster for the ES search head(s) with only CIM-compliant apps installed
- 64-bit OS, minimum 32 GB RAM and 16 processor cores
- Configure search head forwarding
- If enabling Monitoring Console, do not use distributed mode
To which of the following should the ES application be uploaded?
- The indexer
- The dedicated forwarder
- The search head
- The KV store
The search head
What are the reference minimum requirements for OS, CPU, and RAM for an ES search head?
OS: 64 bit
RAM: 32 GB
CPU: 16 cores