Module 8: Network and Other Inputs Flashcards
1
Q
What are network inputs?
A
- TCP/UDP – accept input on any port
- Network services – capture data from syslog or netcat
- Secure – accepted from hosts with correct SSL certs
- Agentless – no need for UF
- Configurations – Splunk Web, conf files and CLI commands
2
Q
What is a Splunk stream?
A
- Splunk-supported free app
* An alternative way to collect ‘difficult’ inputs
3
Q
What is a HTTP event collector?
A
- Fast and efficient – sends data over HTTPS
- Agentless monitoring – directly sends data to Splunk
- Token based – no need for credentials hard-coding
- No configuration overheads – proxies allow for HTTP communication
4
Q
How is a HEC configured?
A
- [http://TokenName] stanza in inputs.conf
- Enable globally
- Unique GUID
- Default port 8088
- Indexer acknowledgement
5
Q
What are the HEC global settings?
A
- [http] stanza contains global settings
- Disabled=true/false
- maxSockets=
- maxThreads=
- outputGroup=
6
Q
What are the HEC per-token settings?
A
- queueSize= KB|MB|GB
- persistentqueueSize=KB|MB|FB
- connection_host
- Index and indexes
7
Q
What is SC4S?
A
Splunk connect for syslog
• Looks like an app, but it’s actually a container
• Preconfigured syslog receiver and a http event log