Module 1: Splunk Cloud Overview Flashcards
What are the three core components of Splunk?
- Indexer
- Search head
- Universal forwarder
What is an indexer?
receives, parses and stores machine data in files. Serves search requests
What is a search head?
web interface for the users. Dispatch searches to indexe
What is a universal forwarder?
collects data from the clients and forwards for indexing
What are the features of a License Master?
o manages Splunk licenses.
o Other Splunk components are license slaves
o Can be a co-located with other components such as Monitoring console
o Licenses can be managed through Splunk Web
What are the features of a Deployment Server?
o Managed configuration files on the deployment clients
o Maintains configuration is serverclass.conf
o Alternative such as ansible / puppet can be used
o Configuration files are packaged as apps
o Deployment clients periodically poll Deployment server
What are the features of a Cluster master?
o Managed the indexer cluster
o There is only one cluster master
o Maintains data bucket status and handles replication
o Distributes configuration files and apps to Cluster members
What are the features of a Search head deployer?
o Distributes apps and configuration files to search head cluster members
o Keeps the files in $SPLUNK_HOME/etc/shd-apps
o Cannot run on the same instance as a cluster member
What are the features of a Monitoring console?
o A Web apps that helps to monitor the system health
o Rich set of charts and stats
o One-stop-shop to monitor everything
o Only admins have access
What are the features of a Heavy Forwarder?
o Can parse data before forwarding to indexer
o Full Splunk enterprise binary with distributed search disabled
o Can also index data locally
o Smaller footprint compared to indexer