Splunk Enterprise 8.0 System Admin - LG1 Flashcards

1
Q

Which installer will you use to install the Search Head?

A

Splunk Enterprise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True or False. When you install Splunk on a Windows OS, you also have to configure the boot-start?

A

False. You only need to do that on a Linux installation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

True or False. The default Splunk Web port is set to 8000.

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the default port for the splunkd process

A

8089

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the $SPLUNK_HOME directory in Windows?

A

C:\Program Files\Splunk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the $SPLUNK_HOME directory in Linux?

A

/opt/splunk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Where is the $SPLUNK_DB located

A

SPLUNK_HOME/var/lib/splunk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the default port for the KV Store?

A

8191

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

True or False. Splunk provides separate licenses for metrics and events data.

A

False. Metrics data draws from the same license quota as event data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

True or False. Search Heads also need an Enterprise License (or set as a slave to License Master with an Enterprise License) even though you have not configured any inputs.

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

True or False. If the indexing exceeds the daily license quota in a pool, your license go into a violation

A

False. If the indexing exceeds the allocated daily quota in a pool, an alert is raised. If it is not fixed by midnight then the alert turns into a warning. 5 or more warnings on an enforced Enterprise license or 3 warnings on a Free license, in a rolling 30-day period, is a violation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

True or False. Write permissions to an app means that the user’s role is able to modify the app.

A

False. User roles with write permission can add/delete/modify knowledge objects used in the app.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

True or False. Universal Forwarders don’t have a web interface, but they can still benefit from an app.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which configuration file tells a Splunk instance to ingest data?

A

inputs.conf

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

True or False. When Splunk starts, configuration files are merged together into a single run-time model for each file type.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

True or False. btool shows on-disk configuration for requested file.

A

True

17
Q

True or False. Splunk, by default, automatically sets the frozen path when you create an index.

A

False. Frozen path is not set by default. Data is set to delete by default.

18
Q

True or False. When hot buckets roll to warm they go to a different directory.

A

False. Hot and warm buckets stay in the same directory by default. When hot buckets roll to warm they are renamed.

19
Q

True or False. _introspection index tracks system performance and Splunk resource usage data.

A

True

20
Q

True or False. Frozen buckets roll to Thawed automatically.

A

False. To thaw a frozen bucket you will have to start by copying the bucket directory from the frozen directory to the index’s thaweddb directory and….

21
Q

True or False. When creating an Index from the web, it creates a stanza in inputs.conf.

A

False. It creates a stanza in indexes.conf.

22
Q

True or False. When running the splunk clean command, you can set a date range for the events you want to delete.

A

False. There is no option to set a date range.

23
Q

True or False. If you are installing a Search Head and an Indexer, Splunk requires an admin account on each instance.

A

True

24
Q

True or False. If you want a role that is “like” user but with some capabilities turned off, you can create a new role that inherits from the user role and remove some of the capabilities.

A

False. You will have to create a new role that does NOT inherit from the user role, turn on all of the same capabilities as in user role, except those you want turned off.

25
Q

True or False. You can unlock a user from the CLI.

A

True

26
Q

True or False. You have to configure a separate receiving port on the indexer for each universal forwarder.

A

False. You do not have to create a separate port for each UF.

27
Q

True or False. When a UF is installed on Windows, the instance provides a GUI.

A

False. Universal Forwarder do not have a GUI on Windows OS or any other OS.

28
Q

Running splunk add forward-server ,indexer:port> creates stanzas in which .conf file?

A

outputs.conf

29
Q

True or False. When adding a Search Peer you must enter a username and password of an account on the search peer, with edit_roles capability.

A

False. The account must have edit_user capability.

30
Q

True or False. Knowledge bundles contain the knowledge objects required by the indexers for searching.

A

True

31
Q

True or False. A quarantined search peer is prevented from performing new searches but continues to attempt to service any currently running search.

A

True

32
Q

True or False. By default the role “user” does not have write permissions within the search app.

A

True