Part 1 Flashcards
Single instance of Splunk Enterprise handles
Input
Parsing
Indexing
Searching
In most splunk deployments ,——-serve as the primary way data is supplied for indexing
Forwarders
This role will only see their own knowledge objects and those that have been shared with them
User
In most production environments,—-will be used as the source of data input
Forwarders
When zooming in on the event time line; a new search is run
False
In a dashboard, a time range picker will only work on panels that include a ——- search
Inline
These roles can create reports
Power,admin.
To keep from overwriting existing fields with your lookup you can use the —— clause
Outputnew
When using a .csv file for lookups, the first row in the file represents this
Field names
The instant pivot button is displayed In the statistics and visualisations tabs when a ————- search is run
Non-transforming
Forwarders
Require minimal resources
Little impact on performance
Reside on machines where data originates
Main components of splunk
Indexer
Search head
Forwarder
Single instance deployment
Input
Parsing
Indexing
Searching
•proof of concept
Personal use
Learning
Might serve needs of small departments sized environments
Splunk cloud
Subscription service
Index up to 5gb per day up to 15 days
Roles
Determine what a user is able to see, do and interact with
Three main roles
Admin- install apps , create knowledge objects for all users
Power- can create and share knowledge objects for users of an app and do real-time searches
Users- will only see their own knowledge objects and those that have been shared with them
Upload, files only get indexed once .csv
Monitor , files & directories,http, tcp,scripts
Forward, receive data From external forwarders
Local files
Http
Indexes
Directories where data is stored
Having separate indexes
Will make data more efficient
Limits data amount splunk searches
Returns only events froM that index
Multiple indexes allow limiting access by user role.
- you control who sees what data
Separate indexes allow custom retention policies.
(Web data index) (6months)
(Main index)
(Security index)(1 year)
Search and reporting app
Default interface
Knowledge objects
Reports
Dashboards
Commands that create statistics and visualisations are called —-
Transforming commands
By default, a search job will remain active for ——
10mins—- after that a new search will have to be run, to keep for longer you can schedule a report
Shared search Jobs Remain active for —-
7days- and readable to everyone
print results or save to PDF
less load on server, more efficient
Export results Will allow you to export events from the job in —— format
Raw
CSV
XML
JSON