Splunk Components Flashcards
1
Q
Splunk main components
A
Forwarder
Indexer
Search head
2
Q
Indexer
A
Process machine data
Put data in structured index as events
Creates files organized in sets of directories by age
Contains raw data (compressed) and indexes (points to raw data)
3
Q
Search heads
A
Search data using SPL
Distributes user search requests to the Indexers
extracts field value pairs from the events
Consolidates results
Knowledge Objects created to extract additional fields and transform the data without changing the underlying index data