Part 1 Flashcards

1
Q

Single instance of Splunk Enterprise handles

A

Input
Parsing
Indexing
Searching

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

In most splunk deployments ,——-serve as the primary way data is supplied for indexing

A

Forwarders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

This role will only see their own knowledge objects and those that have been shared with them

A

User

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

In most production environments,—-will be used as the source of data input

A

Forwarders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

When zooming in on the event time line; a new search is run

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In a dashboard, a time range picker will only work on panels that include a ——- search

A

Inline

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

These roles can create reports

A

Power,admin.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

To keep from overwriting existing fields with your lookup you can use the —— clause

A

Outputnew

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When using a .csv file for lookups, the first row in the file represents this

A

Field names

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The instant pivot button is displayed In the statistics and visualisations tabs when a ————- search is run

A

Non-transforming

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Forwarders

A

Require minimal resources

Little impact on performance

Reside on machines where data originates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Main components of splunk

A

Indexer

Search head

Forwarder

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Single instance deployment

A

Input

Parsing

Indexing

Searching

•proof of concept
Personal use
Learning
Might serve needs of small departments sized environments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Splunk cloud

A

Subscription service

Index up to 5gb per day up to 15 days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Roles

A

Determine what a user is able to see, do and interact with

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Three main roles

A

Admin- install apps , create knowledge objects for all users

Power- can create and share knowledge objects for users of an app and do real-time searches

Users- will only see their own knowledge objects and those that have been shared with them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Upload, files only get indexed once .csv

Monitor , files & directories,http, tcp,scripts

Forward, receive data From external forwarders

A

Local files

Http

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Indexes

A

Directories where data is stored

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Having separate indexes

A

Will make data more efficient

Limits data amount splunk searches

Returns only events froM that index

Multiple indexes allow limiting access by user role.
- you control who sees what data

Separate indexes allow custom retention policies.

(Web data index) (6months)
(Main index)
(Security index)(1 year)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Search and reporting app

A

Default interface

Knowledge objects

Reports

Dashboards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Commands that create statistics and visualisations are called —-

A

Transforming commands

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

By default, a search job will remain active for ——

A

10mins—- after that a new search will have to be run, to keep for longer you can schedule a report

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Shared search Jobs Remain active for —-

A

7days- and readable to everyone
print results or save to PDF
less load on server, more efficient

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Export results Will allow you to export events from the job in —— format

A

Raw

CSV

XML

JSON

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Fast

Smart

Verbose

A

Fast - field discovery is disabled for this mode - speed over complete

Smart- default , balances

Verbose - complete over speed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Timeline

A

Clicking and dragging- moves to past or future events

Zoom in- uses your original search job (re execute )

Zoom out- runs a new search job to return newly selected events(re executes )

Deselect- return to original results

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Default fields

A

Host

Source

Sourcetype

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Interesting fields

A

Have values in at least 20% of the events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

a

#

A

String value (written to left)

Numeral (written to left)

Number to right - number of unique values for the field.

=* any results that contain this field action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

When you add an event to selected fields list —-

A

The field will show where the events occurs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

You can run more efficient searches by ——

A

Using fields in them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Field operators

A

=
!= used with numerical or string values

> =
<
<= numerical values

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Time most efficient - less data you have to search , faster splunk will be.

After time ——

A

Default fields of :

Index
Source
Host
Sourcetype

Most powerful

(The more you tell search , better your results)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Filter

A

Early , faster

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Filter events early in search —-

A

Indexes

Multiple indexes -users can search only what they need to make searches more efficient

Can also be used to limit access

Can search multiple indexes at same time

Wildcards can also be used for index values

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Fields command —-

A

Include or exclude fields from search results

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Fields —-

A

metafields- host, source, sourcetype, index
internal fields-time and raw

Field extraction - costly part of searching , being able to limit fields extracted can make searches more efficient

Field inclusion- happens before field extraction , can improve performance.

Field exclusion- happens after field extraction, only affecting displayed results

Renaming - once renamed , original name is not available to subsequent search commands( can’t access it with original name ) . New field names will need to be used further down the pipeline

fields command allows you to exclude , include specified fields in your search report.
fields+ before(default) improves performance
fields- after table/display easier to read.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Sort command

A

String data- sorted alphanumerically

Numeric data- sorted numerically

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Transforming commands - into visualisations

A

raw data in to data table **transforms events into visualisations
Top- most common default 10 results (table-count,%)
Rare- least common
Stats Commands
chart
time chart
geostats

statistical functions:
count 
dc- groups 
sum- adds 
avg-
min, max, 
list - writes all values 
values -specify and write values once
*count and sum must be within same pipe
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

Reports -Power user

A

Read and write permissions on report (everyone has read access)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Time range picker will only work on panels with an ——

A

Inline search

42
Q

Data models - created by admin & power who understand splunk language

A

Knowledge objects that provide data structure that drives pivots
Data model- framework
Pivot - Interface

Data sets - small collections of data -field names /values

43
Q

Data sets help users—-

A

Find data

Get answers faster

Data sets tab-lists look ups and data models, prebuilt ones make it easier to interact with your data

44
Q

Look ups

A

Categorised as a dataset

Get a lookup file 2 steps :
define lookup table
define a lookup

Can configure look up to run automatically

Look up fields are case sensitive by default

Fields and values to your events that were not included In the index data .
pull data away from standalone files
allow you to add more fields to your events Example : http codes - description(output fields)

.csv
Scripts
Geo

Data useful for search but might not be available in your index

By default- fields in lookup table are returned as output fields , except input field

Outputnew - when you don’t want to overwrite existing fields

45
Q

Additional lookup options

A

Populate lookup table with search results

Define lookup based on external script or command

Use splunk DB connect application

Use geospatial lookups to create queries , to generate chloropleth map visualisations.

Populate events with KV store fields

46
Q

Reports

A

can show events, stats(tables), visualisations(charts), stats and visualisations allow you to drill down by default to see underlying events.
Running multiple reports can put w big demand on system hardware, even if everything is configured to recommended specs

Running a report returns fresh results each time you run it.

Scheduled priority- only available to admin users
Default , higher , highest

  • *time range picker can’t be used on SCHEDULED report!
  • if you add a time range picker-allows you to adjust time range of report when you run it.

Actions to trigger - log event , output results to look up , telemetry endpoint , run a script ,
Send email , webhook

Can disable , embed(anyone with access to web page can see report) ,move , delete reports

*embedded report with not show data until scheduled search is run .
*running a report returns fresh results for each time you run it.
You can edit a report, but not save as new report.
**
You can add scheduled report to a dashboard
for alphanumeric fields-only 3 available reports

User=can only see knowledge objects and what has been shared by them .cant create reports,

47
Q

Alerts

A

Searches that are run on scheduled intervals or in real time

Notify you when results of search meet defined conditions

As soon as alert conditions are satisfied an action is triggered.

Real time alerts are run continuously and can get place more over head on system performance.

Triggered when the search is completed.

Alerts can:
List in interface
Log events 
Output to lookup 
Send to a telemetry endpoint 
Trigger scripts 
Send emails 
Use webhook 
Run a custom alert 

By default :
Every one has read access
Power users have write access

Scheduled and real-time

Throttle - how many times alert is executed.

48
Q

Search job

A

By default -read permissions are private

20 results per page

Saved search 10 mins , can extend to 7 days (doesn’t re execute search)

Can share search- allows multiple users working on same issue to see data( efficient). External copy: 
Raw events 
Csv
XML
JSON

Search history, most recent -5 per page

49
Q

As best practice and performance…

A

Fed up as early in the search as possible

50
Q

Case sensitive

A

Boolean - uppercase

Field names - productId vs productid

Field values from LOOKUP(default) (admin can change this when creating look up tables)

Searching with tags

Reg ex commands

*if commands references a specific value , that value will be case sensitive ex host value www1 rather than WWW1

51
Q

Not case sensitive

A

Search terms
Command names
Clauses
Functions

52
Q

Basic deployment

20gb per day 20 users

A
Searching 
Indexing 
Parsing 
Forwarder management 
Input
53
Q

Multi instance
100gb per day
100 users

A

Searching
Indexing
Parsing
Input

Several hundred forwarders

54
Q

Increasing search capacity

A

Add a search head cluster

  • more users and searches to share resources
  • coordinate activities to handle search requests set of indexers
  • min 3 search heads

Index cluster

  • replicate data
  • prevent data loss
  • availability
  • manage multiple indexers

Non replicating

  • simplified management
  • no availability or data recovery
55
Q

Wildcard*

A

At beginning - all events
Middle - inconsistent
End is better* using OR when possible

56
Q

Search language

A

Command - blue

Function- purple

Argument - green

Boolean/ command modifiers - orange

57
Q

3 methods to create tables and visualisations

A

Select field from fields side bar choose report to run

Use pivot interface, start with data set or instant pivot

Use search language transforming commands in search bar

58
Q

Dashboards

A

One or more panels

Events

Tables

Charts

**reports can be used to create panel of dashboard - exported as PDF or printed

Efficient to create panels from reports- single report. Can be used across different dashboards.

59
Q

Instant pivot

A

Utilise pivot tool without pre existing data model . Can save to dashboard

60
Q

Inputlookup

A

Load results from static look up
good for; review data in csv
validate lookup

61
Q

When looking at a dashboard panel that is based on a report

A

You cannot modify the search string in the panel but you can change and configure the visualisation

62
Q

User account settings and preferences

A

Full names can only be changed by accounts with a power user or admin role .

63
Q

Command to review contents of a specified static lookup file

A

Inputlookup

64
Q

In order to use a lookup table in splunk

A

Lookup file must be uploaded to splunk, lookup definition must be created

65
Q

Values function of stats command

A

Returns a count of unique values for a given field

66
Q

Main requirement for creating visualisations using splunk UI

A

Search must transform event data into XML formatted data first

67
Q

What can be included in the all fields option in terms he side bar

A

Field descriptions

68
Q

Fast-

Smart -

Verbose-

A

Speed

Balance

Completeness

69
Q

The rename command is useful for ——-

A

Giving fields more meaningful names

70
Q

When including spaces or special characters in field names ——

A

Use double straight quotes
rename status as “HTTP status”

Once you rename field you can’t access it with its original name

71
Q

Fields command allows —-

A

You to include or exclude specified fields in your search or report

72
Q

Top command

A

Most common values of given field
10 results
Count and percent columns
Limit count field showperc

73
Q

3 methods for creating stats and visualisations

A

Select a field from fields sidebar, choose report to run

Use pivot interface - dataset, instant pivot

Splunk search language transforming commands in search bar.

74
Q

g.o.d (smart naming)

A

group- name of dept
object- report etc
description- failed logins etc

75
Q

3 main methods of creating tables and visualisations

A

field-fields side bar & choose report to run
pivot interface, dataset or instant pivot
splunk search language, transforming commands in the search bar

76
Q

why create panels from reports?

A

a single report can be used across different dashboards

77
Q

if lookup is not configured to run automatically

A

use lookup command in your search to use lookup fields

78
Q

output argument is optional

A

if not specified, lookup returns all fields from the lookup table except the match fields

79
Q

outputnew

A

do not want to overwrite existing fields

80
Q

after time most powerful keywords are

A

host, spurce, sourcetype

81
Q

use fields commands to use

A

only fields you need

82
Q

search job inspector

A

header
execution costs
search job properties

83
Q

the instant pivot button is displayed after a —

A

non transforming search is run

84
Q

data models are made up of datasets

A

look up is categorised as a dataset

85
Q

pivot

A

can be displayed as; table or visualisation

can be saved as report, and can include a time range picker

86
Q

splunk deployed—

A

enterprise , light, cloud

87
Q

apps available from—-

A

splunkbase, or admins can build their own

88
Q

enhance solutions

A

ITSI
ES
UBA

89
Q

Search and reporting app

A

knowledge objects , reports , dashboards

90
Q

data summary

A

host , source , sourcetype

91
Q

components

A

indexer, search head, forwarder

92
Q

additional splunk components

A

deployment server, cluster master, license master

93
Q

adding a search head cluster

A

more users for search and share. 3 search heads

94
Q

can add data inputs

A

cli, splunk web, input.conf, splunkbase

95
Q

click any item in search results (options)

A

add to search, exclude , new search

96
Q

search result layout

A

raw , list , table

97
Q

save as:

A

Report, dashboard panel, alert

98
Q

report types

A

numeric- 6 report types

alphanumeric- 3 report types

99
Q

pivot

A

can be displayed as; table or visualisation

100
Q

instant pivot

A

Use pivot without pre existing data model, executes search without commands
can select fields to be included in data model object

101
Q

lookup fields are–

A

case sensitive

102
Q

severity of triggered alerts—

A

low, medium, high, critical