quiz 1 Flashcards
Machine data is always structured.
False
Machine data is only generated by web servers.
False
Machine data makes up for more than ___% of the data accumulated by organizations.
90%
index data
collect data from any source
search & investigate
data
add knowledge
label data for uniform
Which of these is not a main component of Splunk? earch and investigate
Collect and index data
Compress and archive
Add knowledge
Compress and archive
What are the three main processing components of Splunk?
Forwarders
Search Heads
Indexers
Which function is not a part of a single instance deployment? Clustering
Searching
Indexing
Parsing
Clustering
In most Splunk deployments, ________ serve as the primary way data is supplied for indexing.
Forwarders
Search requests are processed by the ___________.
Indexers
from the splunk bar you can
switch between apps, edit account, view messages, edit configs, monitor search jobs, help
app bar
navigate system
what are transforming commands
commands that create statistics and visualizations
search job is active for
10 minutes
shared job good for
7 days
order of boolean
not, or, and
field values are case sensitive
false
wildcards can be used in field searches
yes
field names are
case sensitive
what attributes describe “a dest 4”
a means contains string values and 4 values
@ symbol does
round down. if 9:37, you will get results up until 9
different index examples
security data, web data
Having separate indexes allows:
Faster Searches.
Multiple retention policies
Ability to limit access
As a general practice, exclusion is better than inclusion in a Splunk search.
False
What is the most efficient way to filter events in Splunk?
by time
Time to search can only be set by the time range picker.
False