Splunk Enterprise 8.0 System Admin - LG1 Flashcards

1
Q

Which installer will you use to install the Search Head?

A

Splunk Enterprise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True or False. When you install Splunk on a Windows OS, you also have to configure the boot-start?

A

False. You only need to do that on a Linux installation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

True or False. The default Splunk Web port is set to 8000.

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the default port for the splunkd process

A

8089

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the $SPLUNK_HOME directory in Windows?

A

C:\Program Files\Splunk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the $SPLUNK_HOME directory in Linux?

A

/opt/splunk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Where is the $SPLUNK_DB located

A

SPLUNK_HOME/var/lib/splunk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the default port for the KV Store?

A

8191

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

True or False. Splunk provides separate licenses for metrics and events data.

A

False. Metrics data draws from the same license quota as event data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

True or False. Search Heads also need an Enterprise License (or set as a slave to License Master with an Enterprise License) even though you have not configured any inputs.

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

True or False. If the indexing exceeds the daily license quota in a pool, your license go into a violation

A

False. If the indexing exceeds the allocated daily quota in a pool, an alert is raised. If it is not fixed by midnight then the alert turns into a warning. 5 or more warnings on an enforced Enterprise license or 3 warnings on a Free license, in a rolling 30-day period, is a violation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

True or False. Write permissions to an app means that the user’s role is able to modify the app.

A

False. User roles with write permission can add/delete/modify knowledge objects used in the app.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

True or False. Universal Forwarders don’t have a web interface, but they can still benefit from an app.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which configuration file tells a Splunk instance to ingest data?

A

inputs.conf

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

True or False. When Splunk starts, configuration files are merged together into a single run-time model for each file type.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

True or False. btool shows on-disk configuration for requested file.

17
Q

True or False. Splunk, by default, automatically sets the frozen path when you create an index.

A

False. Frozen path is not set by default. Data is set to delete by default.

18
Q

True or False. When hot buckets roll to warm they go to a different directory.

A

False. Hot and warm buckets stay in the same directory by default. When hot buckets roll to warm they are renamed.

19
Q

True or False. _introspection index tracks system performance and Splunk resource usage data.

20
Q

True or False. Frozen buckets roll to Thawed automatically.

A

False. To thaw a frozen bucket you will have to start by copying the bucket directory from the frozen directory to the index’s thaweddb directory and….

21
Q

True or False. When creating an Index from the web, it creates a stanza in inputs.conf.

A

False. It creates a stanza in indexes.conf.

22
Q

True or False. When running the splunk clean command, you can set a date range for the events you want to delete.

A

False. There is no option to set a date range.

23
Q

True or False. If you are installing a Search Head and an Indexer, Splunk requires an admin account on each instance.

24
Q

True or False. If you want a role that is “like” user but with some capabilities turned off, you can create a new role that inherits from the user role and remove some of the capabilities.

A

False. You will have to create a new role that does NOT inherit from the user role, turn on all of the same capabilities as in user role, except those you want turned off.

25
True or False. You can unlock a user from the CLI.
True
26
True or False. You have to configure a separate receiving port on the indexer for each universal forwarder.
False. You do not have to create a separate port for each UF.
27
True or False. When a UF is installed on Windows, the instance provides a GUI.
False. Universal Forwarder do not have a GUI on Windows OS or any other OS.
28
Running splunk add forward-server ,indexer:port> creates stanzas in which .conf file?
outputs.conf
29
True or False. When adding a Search Peer you must enter a username and password of an account on the search peer, with edit_roles capability.
False. The account must have edit_user capability.
30
True or False. Knowledge bundles contain the knowledge objects required by the indexers for searching.
True
31
True or False. A quarantined search peer is prevented from performing new searches but continues to attempt to service any currently running search.
True
32
True or False. By default the role "user" does not have write permissions within the search app.
True