Splunk Cloud Overview Flashcards
What does Splunk Cloud provide?
- Hosted and supported by Splunk
- Enterprise functionality and features hosted on someone else’s machines
- Reliability for data processing and search
- Faster time to value with Splunk managed environment and hosted software. Reduced infra investment.
Splunk Cloud deployment is ______.
Automated, highly flexible, and scalable.
True or False: Splunk Cloud has the same components as Splunk Enterprise.
True.
What are the components of Splunk?
- Universal and/or Heavy Forwarders
- Search Head
- Indexer(s)
- Manager Node
- License Manager
What components of a Splunk Cloud deployment are considered on-prem/customer cloud?
- Universal/Heavy Forwarders
- Optional Intermediate UF/HF
What components of a Splunk Cloud deployment are considered hosted?
- Search Head(s)
- Indexer(s)
- Manager Node
- License Manager
What is required to access Forwarders?
SSL secure connection access.
What are customer responsibilities in a Splunk Cloud deployment?
- Forwarding data to Splunk
- Managing configurations such as source type, index and contextual details
- Administer and coordinate changes to manage users, data retention, config and maintenance, license, ingestion, etc.
What aspects of a Splunk Cloud deployment are managed by Splunk?
Reliability.
- Ingestion and data management
- Indexing and storage of data
- Searchable data access
What licensing options are available to Splunk Cloud customers?
- Ingestion based
- Infrastructure usage-based
How is license option determined for a customer?
Based on:
- Current and future ingestion size
- Correct sizing calculated on potential workload
- Need for flexibility and scalability
Ingestion violations are _____.
Not enforced.
They are monitored and adjustments to volume or infrastructure resourcing is done on:
- Usage review of consumption
- To meet performance challenges and customer growth.
How does ingestion licensing work?
Aggregated daily volume of data indexed as GB/day of data ingest.
- All Splunk capabilities at a set cost for ingesting data
- No additional costs to increase resources for index or search activities.
- Additional data can be purchased to the next ingest level available or to unlimited data volumes.
How does workload/infrastructure licensing work?
Splunk Virtual Core (SVC) units of data processing capacity used for a mix of ingest and search.
- All Splunk capabilities at a set cost of a fixed size infrastructure deployed.
- No ingestion violation - allowed unmetered ingest
How are Splunk Virtual Cores (SVCs) measured?
SVCs are measured as units of Compute, Memory, and I/O resources consumed by Splunk processes.
What are the benefits of Splunk Cloud?
- Advice and troubleshooting support
- Asset management and automated infra deployment
- Automated processing and implementation
- Regular maintenance and upgrade
- Monitoring and alerting of system health and security
- IT ops and Security specialists
- 24/7 Network Operation Center
What are Splunk Cloud’s Secure Controls
- Limited managed access to host components
- Search Head GUI access only
- No CLI access
- No License pooling
Cloud Application Vetting compliance - Installed apps should comply to vetting policy, ensures data security and improved platform visibility
- Secure forwarding using Forwarder Credentials App
- Secure SSL and TLS forwarding unique to customer environment
What are the two designations of Splunk Cloud deployments?
- Classic
- Victoria
What is the difference between Splunk Cloud Classic and Victoria deployments?
- HEC Configuration
- Hybrid Search (not supported in Victoria)
- IDM (No IDM on Victoria experience)
- Self-Service App Installation
What is the difference in CLI from On-Prem and Cloud?
On-prem supports CLI, Cloud does not have access.
What is the difference in Apps from On-Prem and Cloud?
On-prem customers decide what apps run in a deployment, Cloud customers can only install vetted and approved apps.
What is the difference in Direct TCP and syslog inputs from On-Prem and Cloud?
On-prem supports these, Cloud customers cannot send these directly to Splunk Cloud.
What is the difference in Scripted alerts from On-Prem and Cloud?
On-prem supports these, Cloud only supports them in the context of approved apps.
What is the difference in License pooling from On-Prem and Cloud?
Supported on-prem, not supported in Cloud
What is the difference in HEC from On-Prem and Cloud?
On-prem has it enabled by default, Splunk Cloud has it enabled via ELB on port 443.
What is the difference in Splunk API from On-Prem and Cloud?
On-prem has it enabled by default, Cloud has it accessible by Cloud Support and API Self-service App
What is the difference in Network Connection from On-Prem and Cloud?
On-prem can use TCP and UDP, optional secure connection; Cloud can use inbound TCP only with SSL secure connection.