Splunk Components Flashcards

1
Q

Splunk main components

A

Forwarder
Indexer
Search head

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Indexer

A

Process machine data
Put data in structured index as events
Creates files organized in sets of directories by age
Contains raw data (compressed) and indexes (points to raw data)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Search heads

A

Search data using SPL

Distributes user search requests to the Indexers

extracts field value pairs from the events

Consolidates results

Knowledge Objects created to extract additional fields and transform the data without changing the underlying index data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly