Module 3 - Licensing Splunk Flashcards

1
Q

License types

A

Enterprise trail - valid for 60 days. Up to 500mb logs a day
Enterprise
Free license - disables alerts, schedule searches, authentication, clustering, distributed search, forwarding to non splunk servers, summarization
Forwarder license

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Ingest pricing

A

Based in data volumes
Traditional method
Monitored in MC AND Settings > Licensing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Workload pricing

A

Based on compute capacity
Monitored in MC (vCPU) or cloud monitoring console (for SVCs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Daily quota includes

A

Data from all sources that is indexed
Events - measured as data (full size)
Metrics - first 150 bytes per metric event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Daily quota does not include

A

Replicated data (index clusters)
Summary indexes
Internal logs: _internal, _audit, indexes
Components of the index: metadata, tsidx, etc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

License requirements by server role and data

A

Search heads, deployments servers require license even if not ingesting data
Indexers need license to determine amount of allowed ingested data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Licenses folder location

A

SPLUNK_HOME/etc/licenses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Add license from CLI

A

Splunk add license <key></key>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Multiple licenses behaviour

A

Multiple licenses stacked
All instances collectively share stack entitlement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

License pooling

A

Licenses can be subdivided and assigned to indexer groups (multi tenant scenario)
Most common single pool with shared entitlement
Warnings and violations per pool

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

License alerts

A

Occurs when indexing exceeds the allocated daily quota in a pool
View from WebUI > Messages

Cleared at midnight when daily allocation is reset; may result in a Warning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

License warnings

A

Occurs if an alert is triggered and license capacity is not increased by midnight
Occurs only once per day

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

License violations

A

Occur after 5 warnings in a rolling 30 day period
Does not affect indexing or searches
Searches are disabled for licenses < 100 GB/day with 45 warnings in a rolling 60-day period
Require reset key from splunk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Monitoring console

A

On prem and cloud (CMC)

Provides vCPU / SVC usage across workloads
– By search type, indexes, and source types, etc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Splunk app for chargeback

A

On prem and cloud

Provides Search Resource Usage
(SRU) across business units – 1 SRU ~= 1 SVC
Provides forecasts using Splunk Machine Learning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Event and metric licensing

A

Metrics data draws from the same license quota as event data

17
Q

Metric cap

A

Metrics measurement is capped at 150 bytes per metric event

18
Q

What components require enterprise licensing

A

Search Heads, Indexers, Heavy Forwarders, Deployment Server and other Splunk Enterprise instances require the Enterprise license even if they are not ingesting data.

19
Q

What component doesn’t require Enterprise licensing

A

Universal forwarder

20
Q

Alerts, warning and violation transition

A

Indexing that exceeds the allocated daily quota in a pool is an alert. An alert not fixed by midnight turns into a warning. 5 or more warnings on an enforced Enterprise license (or 3 warnings on a Free license) in a rolling 30-day period is a violation