Splunk Core Certified User Flashcards
what are considered hosts by splunk ?
computers, sensors, virtual machines, web servers, network devices, databases
hosts usually generate a variety of data including
fault
configuration
accounting
performance
security
system logs
application logs
metrics
tickets
where can splunk index data from ?
- can index from any source
what are the processing components of splunk ?
indexers
forwarders
search heads
what are the management components of splunk ?
- Deployment servers
- indexer cluster manager
- search head cluster deployment
- license manager
- monitoring console
what can a search head do once connected ?
- search
- analyze
- visualize
- reports
- alerts
- dashboard
- knowledge
what are some details about splunk forwarders ?
forwarders are generally installed on host machines to collect source data and send to splunk
forwarders are the primary way to send data to splunk for indexing
what are the two types of splunk forwarders ?
-Universal forwarder
Heavy forwarders
- configured from full splunk enterprise installation
- can parse and filter before forwarding
what is a splunk component that resides on machines originating data ?
forwarder
what is the difference between universal and heavy forwarders
heavy forwarders can parse data
how does splunk data flow initially ?
data from hosts —> Indexer —-> indexes on disk
what is an indexer in splunk ?
An indexer or search peer is a Splunk enterprise instance that processes and writes data into repositories as events
what is processing in regards to splunk?
- transform data into events
- assign metadata
- identify or create timestamps
- data repositories are known as indexes
- repositories containing files with index data are called buckets
what is thawed data in splunk ?
thawed data in splunk is when you are bringing data out of the archive
what is an Indexer cluster ?
- an indexer cluster is when you group indexers together to provide data replication
- cluster manager - coordinates replication activities and manages the cluster
what is a splunk component that transforms raw data into events?
indexer and heavy forwarders are the splunk components that transform raw data into events
what are some of the details regarding search heads
- allows users to write search queries SPL to search the indexed data
- distributes search requests to the indexers and merges the result back to the user
Can create fields and other knowledge objects such as
- reports
- alerts
- visualizations
- dashboards
what are some details regarding the search head cluster ?
- groups of search heads with identical configuration
- search requests from users are balanced across the SH groups
- Managed by a cluster captain
- cluster deployer, distributes apps and other configuration to cluster members
what are some details of the configuration deployment server?
- distributes content, configuration, apps to other groups of splunk instances
- distributed content is known as deployment apps
- used mostly to distribute apps to splunk forwarders
what is the forwarder manager for Splunk ?
provides a way to configure deployment servers and monitor updates
what is the license manager in Splunk ?
Hosts licenses and assigns license volume to other splunk components in a distributed deployment
License meter runs during indexing
License types
- Volume based
- Infrastructure based
- Access to splunk features
what is the monitoring console in Splunk ?
Used to view topology and performance information.
what are the three main out of the box roles in Splunk ?
User
Power
Admin
what are some of the default app examples ?
home app
search app