Introducing Splunk Flashcards
1
Q
What are Splunk apps (1)
A
Collection of files containing data inputs, UI elements, knowledge objects
2
Q
What are Splunk apps (2)
A
Apps allow different workspaces for specific use cases or user roles to co-exist on same Splunk server
3
Q
Search and reporting app
A
Default interface for searching and analyzing data
Allows user to create knowledge objects, reports, dashboards
4
Q
Host
A
Unique identifier where events originated (host name, ip, etc)
5
Q
Source
A
Name of stream, file or other input
6
Q
Sourcetype
A
Specific data type or data format. Parser to parse known log format