Module 8: Network and Other Inputs Flashcards

1
Q

What are network inputs?

A
  • TCP/UDP – accept input on any port
  • Network services – capture data from syslog or netcat
  • Secure – accepted from hosts with correct SSL certs
  • Agentless – no need for UF
  • Configurations – Splunk Web, conf files and CLI commands
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a Splunk stream?

A
  • Splunk-supported free app

* An alternative way to collect ‘difficult’ inputs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a HTTP event collector?

A
  • Fast and efficient – sends data over HTTPS
  • Agentless monitoring – directly sends data to Splunk
  • Token based – no need for credentials hard-coding
  • No configuration overheads – proxies allow for HTTP communication
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How is a HEC configured?

A
  • [http://TokenName] stanza in inputs.conf
  • Enable globally
  • Unique GUID
  • Default port 8088
  • Indexer acknowledgement
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the HEC global settings?

A
  • [http] stanza contains global settings
  • Disabled=true/false
  • maxSockets=
  • maxThreads=
  • outputGroup=
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the HEC per-token settings?

A
  • queueSize= KB|MB|GB
  • persistentqueueSize=KB|MB|FB
  • connection_host
  • Index and indexes
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is SC4S?

A

Splunk connect for syslog
• Looks like an app, but it’s actually a container
• Preconfigured syslog receiver and a http event log

How well did you know this?
1
Not at all
2
3
4
5
Perfectly