Module 2 - Monitoring Splunk Flashcards

1
Q

Content to monitor in MC

A

Search
Indexing
Resources
Forwarders
Instances

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Configure MC in standalone mode

A

Setting > general setup
Select mode: Standalone
Apply changes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

MC in Distributed Mode

A

Recommended on its own system
Same requirements as search head

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

MC on shared instance

A

With License Manager
With deployment server (50< clients)
With indexer cluster Manager node

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Adding Splunk Instances to the MC

A

Repeat for each Search Head, Deployment Server, License Manager, and non-clustered Indexer

Settings > distributed search > Search peers > New peer >Save

DO NOT add clustered indexers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

MC Alerts

A

Disabled by default

Settings > Alert Setup

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

MC Health Check

A

Series of ad hoc searches that run sequentially:
Monitoring Console > Health Check

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Splunk Assist

A

Cloud connected service
Insights in real time
Leverages Telemetry data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Splunk diag

A

./splunk diag
Collects server specs: configure, os, file system and open current connections
Collect splunk platform data: Contents of SPLUNK_HOME/etc such as app configurations, Splunk log files, and index metadata

Creates tar.gz file and diag.log

Does not retrieve customer or index data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Diagnostics in Splunk web

A

Instrumentation Settings > System > Instrumentation

RapidDiag - directly uploads to splunk support (Only Linux)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly