Splunk Enterprise 8.0 System Admin - LG1 Flashcards
Which installer will you use to install the Search Head?
Splunk Enterprise
True or False. When you install Splunk on a Windows OS, you also have to configure the boot-start?
False. You only need to do that on a Linux installation.
True or False. The default Splunk Web port is set to 8000.
True.
What is the default port for the splunkd process
8089
What is the $SPLUNK_HOME directory in Windows?
C:\Program Files\Splunk
What is the $SPLUNK_HOME directory in Linux?
/opt/splunk
Where is the $SPLUNK_DB located
SPLUNK_HOME/var/lib/splunk
What is the default port for the KV Store?
8191
True or False. Splunk provides separate licenses for metrics and events data.
False. Metrics data draws from the same license quota as event data.
True or False. Search Heads also need an Enterprise License (or set as a slave to License Master with an Enterprise License) even though you have not configured any inputs.
True.
True or False. If the indexing exceeds the daily license quota in a pool, your license go into a violation
False. If the indexing exceeds the allocated daily quota in a pool, an alert is raised. If it is not fixed by midnight then the alert turns into a warning. 5 or more warnings on an enforced Enterprise license or 3 warnings on a Free license, in a rolling 30-day period, is a violation.
True or False. Write permissions to an app means that the user’s role is able to modify the app.
False. User roles with write permission can add/delete/modify knowledge objects used in the app.
True or False. Universal Forwarders don’t have a web interface, but they can still benefit from an app.
True
Which configuration file tells a Splunk instance to ingest data?
inputs.conf
True or False. When Splunk starts, configuration files are merged together into a single run-time model for each file type.
True