Module 1: Introducing Splunk Flashcards

1
Q

5 Things Splunk Allows You to Do

A
  1. Index Data
  2. Search & Investigate
  3. Add Knowledge
  4. Monitor & Alert
  5. Report & Analyze
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Splunk uses these 3 tool categories:

A
  1. Application Management
  2. Operations Management
  3. Security & Compliance
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does Splunk do? (the 3 a’s)

A

It allows you to aggregate, analyze, and get answers from machine data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

True or False: Splunk allows you to index data from any source.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How is Splunk Enterprise deployed?

A

Components installed and administered on-premises.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How is Splunk Cloud deployed?

A

Splunk Enterprise as a scalable service. No infrastructure required.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Splunk Light?

A

Solution for small IT environments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are Splunk apps? (hint: UC,FC,UP)

A
  1. Address a wide variety of use cases and to extend the power of Splunk.
  2. Collections of files containing data inputs, UI elements, and/or knowledge objects
  3. Allows multiple workspaces for different use cases/user roles to co-exist on a single Splunk instance
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the functionality of user roles in Splunk?

A

They determine users’ capabilities and data access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the 3 main roles out of the box?

A
  1. Admin
  2. Power
  3. User
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

True or False: Power users can create additional roles

A

False - only admins can do this

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does the Search & Reporting App do? (2 things)

A
  1. Provides a default interface for searching and analyzing.

2. Enables you to create knowledge objects, reports, and dashboards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Data Summary Tab - Define “Host”

A

Unique identifier of where the events originated (host name, IP Address, etc.)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Data Summary Tab - Define “Source”

A

Name of the file, stream, or other input

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Data Summary Tab - Define “Sourcetype”

A

Specific data type or data format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly