Splunk Enterprise 8.0 Data Admin - LG1 Flashcards

1
Q

Which installer will the System Admin use to install the heavy forwarder?

A

Splunk Enterprise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which configuration file tells a Splunk instance to ingest data?

A

inputs.conf

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

True or False. The best place to add a parsing configuration on an indexer would be the SPLUNK_HOME/etc/system/local directory, as it has the highest precedence.

A

False. Best practice is to put the configuration in an app’s local directory (SPLUNK_HOME/etc/apps//local).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When you configure the inputs using Settings > Add Data, under what directory is the inputs.conf created?

A

It depends on the App Context setting on the Input Setting stage. Best practice is to put the configuration file in the local directory of your app. If you have clustering enabled, then the SPLUNK_HOME/etc/system/local may not be the highest in the precedence order.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

True or False. You cannot change the sourcetype when you go through the Settings > Add Data wizard.

A

False. You can change the sourcetype from the dropdown. In fact, you can even create a new sourcetype.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

True or False. Splunk will not create an inputs.conf file when you use the Upload option in Settings > Add Data.

A

True. Upload is a one-time process, so Splunk does not create an inputs.conf.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

If the forwarder is set to send its data to 2 indexers at 30 seconds intervals, does it switch exactly at the 30th second?

A

Not always. The forwarder does not want to send half an event to indexer1 and the other half to indexer2. To avoid this situation, for example, if the forwarder is tailing a file, then it waits for an EOF or a pause in IO activity before it switches.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

True or False. Turning SSL on between the forwarder and the receiver automatically compresses the feed.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What configuration file on the forwarder defines where data is to be forwarded to?

A

outputs.conf

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

True or False. The HF has a GUI.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

True or False. The UF and the HF can be used to mask data before transmitting to indexers.

A

False. Only the HF, specifically a Splunk Enterprise instance, can perform data masking.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

True or False. The default listening port is 8089.

A

False. 8089 is the default management port. The listening port can be any port.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

On the DS, what is the difference between the apps sitting in the SPLUNK_HOME/etc/apps folder versus the SPLUNK_HOME/etc/deployment-apps?

A

The apps in the …/etc/apps folder are for the Deployment Server and the apps in the …/etc/deployment-apps are apps for deployment to a client.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When an app is deployed from the Deployment Server to the client, where will you find that app on the client by default?

A

Apps by default are deployed from the DS to the client in the SPLUNK_HOME/etc/apps folder.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

True or False. Clients poll the DS on port 9997.

A

False. Clients poll the DS on its management port (8089 by default).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

True or False. You can use the wildcards, … and * in the whitelist and blacklist.

A

False. The wildcards, … and * are meant for the stanzas.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

True or False. The host_regex setting in inputs.conf can extract the host from the filename only.

A

False. It can extract the host from the path of the file.

18
Q

After a file monitor is set up and is running, if you change the host value, will the new host value be reflected for already ingested data?

A

No. All changes apply to the new data only. To reflect changes for your old data, you need to delete and re-ingest the old data.

19
Q

In our environment, we have a UF, an Indexer and a SH. Which instance contains the _thefishbucket?

A

Each instance will have its own local _thefishbucket

20
Q

True or False. Persistent Queue and Memory Queue can be applied to Network as well as Scripted inputs.

A

True

21
Q

Why is it a Best Practice to send data to a syslog collector that writes into a directory structure and then have a UF/HF ingest the data from the directory structure?

A

If the UF has to be restarted, the _fishbucket will prevent data loss.

22
Q

True or False. An interval setting for scripted inputs can be specified in cron syntax.

A

True. You can specify the interval in either number of seconds or cron syntax.

23
Q

Is it possible to use the host value and not the DNS name or IP address for a TCP input? How?

A

Yes, it is possible. Under the stanza in inputs.conf set the connection_host to none and specify the host value.

24
Q

True or False. You can set up a windows input using a UF on the windows server and send the data to an Indexer running on Linux.

A

True

25
Q

True or False. You can collect Active Directory data from a Windows Server remotely using wmi.conf

A

False. Only event logs and performance monitoring logs can be collected using wmi.conf.

26
Q

True or False. Event Collector can be set up on a UF.

A

False. Even Collector can be set up on an Indexer or HF.

27
Q

True or False. Data can be sent in json or any raw data format to the event collector

A

True

28
Q

In the props.conf example below, what is sendmail?

[sendmail]
CHARSET=AUTO

A

It is a sourcetype in props.conf.

Source types are specified as a string value in the stanza without the sourcetype:: prefix.

29
Q

Examine the props.conf example below. Is this an acceptable format for the stanzas?

[source::/var/…/korea/*]
CHARSET=EUC-KR

[sendm*]
CARSET=AUTO

A

No. You cannot use a wildcard with source types in props.conf.

30
Q

True or False. Time extraction can be done using props.conf on the UF and the HF.

A

False. If the file does not contain a header line, then time has to be extracted on the HF/Indexer.

31
Q

True or False. Event boundaries can be defined using props.conf at the UF.

A

True. You may want to define event boundaries for certain event types at the UF level. Remember the more you do at the UF level, the more resources you will need.

32
Q

True or False. When extracting a timestamp, if the parser finds the indexer’s OS time, it will use that as the first preference.

A

False. When all else fails, the Indexer’s OS time is used as the last preference.

33
Q

True or False. sedcmd can be used to eliminate unwanted events.

A

False. In order to eliminate unwanted events. you have to use transforms.conf.
sedcmd can only be used to mask or truncate data.

34
Q

True or False. When using tarnsforms.conf, the SOURCE_KEY is set to _raw by default

A

True. If you do not specify the SOURCE_KEY in transforms.conf, it defaults to _raw.

35
Q

In the props.conf file example below, what is itops?

[mysrctype]
TRANSFORMS-itops = route_errs_warns

A

itops is the namespace and is used to determine the sequence.

36
Q

True or False. props.conf and transforms.conf are used to store Field Extractions, Lookups, Saved Searches and Macros.

A

False. The are used for Field Extractions and Lookups.

37
Q

True or False. Any user belonging to any user role has the ability reassign any Knowledge Object (KO).

A

False. Only users belonging to the admin role can assign any KO.

38
Q

True or False. When you are using Splunk Web and select REGEX option in the Field Extractor, it uses props.conf and transforms.conf in the background.

A

False. It only uses props.conf. Delimiter based extractions entries in props.conf and transforms.conf are manually created.

39
Q
which setting in indexes.conf allows data retention to be controlled by time?
A. maxDaysToKeep
B. moveToFrozenAfter
C. maxDataRetentionTime
D. frozenTimePeriodInSecs
A

D

40
Q

In case of a conflict between a whitelist and a blacklist input settings, which one is used?
A. Blacklist
B. Whitelist
C. They cancel each other out
D. Whichever is entered into the configuration first

A

A

41
Q
In which Splunk configuration is the sedcmd USED?
A. props.conf
B. inputs.conf
C. indexes.conf
D. transforms.conf
A

A

42
Q
Which parent directory contains the configuration files in Splunk?
A. $SPLUNK_HOME/etc
B. $SPLUNK_HOME/var
C. $SPLUNK_HOME/conf
D. $SPLUNK_HOME/default
A

A