Splunk_1 Flashcards

1
Q

What is Machine Data ?

A

Digital information created by the activity of computers, mobile phones, embedded systems and other networked devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What Splunk Do ?

A

Searching, monitoring, and examining machine-generated Big Data through a web-style interface.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the main components of Splunk?

A

Forwarder
Indexer
Search Head

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are forwarder ?

A

An agent you deploy on IT systems, which collects logs and sends them to the indexer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Splunk ?

A

A distributed system that aggregates, parses and analyses log data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the two types of forwarder ?

A
  • Universal Forwarder

- Heavy Forwarder

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Universal forwarder for ?

A

It forwards the raw data without any prior treatment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Heavy Forwarder for ?

A

Parsing and indexing at the source, on the host machine and sends only the parsed events to the indexer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is indexer for ?

A

Transforms data into events (unless it was received pre-processed from a heavy forwarder), stores it to disk and adds it to an index, enabling searchability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is SearchHead for ?

A

Search and query Splunk data, and interfaces with indexers to gain access to the specific data they request.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the three processing tiers for a splunk deployment ?

A
  • Data input
  • Indexing
  • Search management
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the correspondence between the three typical processing tiers and the four data pipeline segments ?

A
  • The data input tier handles the input segment.
  • The indexing tier handles the parsing and indexing segments.
  • The search management tier handles the search segment.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the 5 main function of Splunk Enterprise ?

A
  • Index Data
  • Search & investigate
  • Add knowledge
  • Monitor & alert
  • Report & analyse
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the different product categories of Splunk ?

A

Splunk Enterprise − It is used by companies which have large IT infrastructure and IT driven business.

Splunk Cloud − It is the cloud hosted platform with same features as the enterprise version. It can be availed from Splunk itself or through the AWS cloud platform.

Splunk Light − It allows search, report and alert on all the log data in real time from one place.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is splunk role ?

A

Determine what a user is able to see, do or interact with.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the 3 main roles in Splunk Enterprise ?

A
  • Administrator role
  • Power role
  • User role
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Who can add data to Splunk ?

A

The administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are the 3 option to ingest data to Splunk ?

A
  • Upload file from the computer (local files)
  • Monitor files and ports on the splunk platform instance
  • Forward data form a splunk forwarder
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is an event ?

A

A set of values associated with a

timestamp. It is a single entry of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is SourceType ?

A

A default field that identifies the data structure of an event. A source type determines how formats the data during the indexing process.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is the Host Value ?

A

The name of the machine from which the event originates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What is index ?

A

The directory where the data will be stored

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is knowledge object ?

A

A user-defined entity that enriches the existing data. You can use knowledge objects to get specific information about your data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What are the five components of splunk language ?

A
  • Search terms
  • Commands
  • Functions
  • Arguments
  • Clauses
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Are Field values case sensitive ?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Are Field Name case sensitive ?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What is the most efficient way to filter events ?

A

Using Time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Can Splunk allow searches in real time ?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

The colors in SPL

A

Orange for boolean
Blue for commands
Green for command arguments
Purple for functions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Which command removes results with duplicate field values?

A

Dedup

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Can Charts be based on numbers, time, or location ?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Can the User role create report ?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What Splunk uses to categorize the type of data being indexed ?

A

Sourcetype

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Are events always returned in chronological order ?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

What separate indexes allows ?

A

Multiple retention policies
Faster Searches.
Ability to limit access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

What is a lookup ?

A

Add custom fields to event from external sources like csv.file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Which command returns a table containing only specified fields in result set ?

A

Table command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Which command renames a field in results ?

A

Rename command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Which command includes or excludes specified fields. ?

A

Fields command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

Which command sorts results by specified field ?

A

Sort command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Which command adds field values from an external source (e.g., csv files) ?

A

Lookup command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

What is the transition that takes place as the buckets age in Splunk?

A

They roll from hot to warm to cold

43
Q

What does each bucket have?

A

Its own raw data, metadata, and index files

44
Q

What are Booleans in the Splunk Search Language ?

A

NOT
OR
AND

45
Q

How warm Buckets in Splunk indexes are named by ?

A

The timestamps of first and last event in the bucket

46
Q

What are the searches mode ?

A

Verbose
Fast
Smart

47
Q

Which of the search modes automatically returns all extracted fields in the fields sidebar?

A

Verbose

48
Q

Which type of visualization allows you to show a third dimension of data?

A

Bubble Chart

49
Q

Which option is NOT available with the chart and timechart commands?

A

Usefill

50
Q

What the timechart command buckets data in time intervals depending on ?

A

The selected time range

51
Q

Which clause allows you to define which field is represented on the X axis of a chart ?

A

Over

52
Q

Can the iplocation and geostats commands be used together ?

A

Yes

53
Q

Which options are valid with the chart command?

A

Useother

Usenull

54
Q

What the Gauge command allow you ?

A

To set colored ranges for a single-value visualization.

55
Q

Which command will compute the sum of numeric fields within events and place the result in a new field ?

A

Addtotals

56
Q

What arguments the trendline command requires ?

A

Trend type,
Time period
Field

57
Q

Does the search job inspector shows how long a given search took to run ?

A

Yes

58
Q

Which are stats function ?

A

avg
count
sum

59
Q

What search returns can be viewed as a chart ?

A

Statistics

60
Q

Which axis should always be numeric ?

A

the Y axis

61
Q

What is the gauge command for ?

A

Allows you to set colored ranges for a single-value visualization.

62
Q

Which argument (in order) the eval command ‘if’ function requires ?

A

boolean expression, result if true, result if false

63
Q

If you want to format values without changing their characteristics, which would you use?

A

The fieldformat command

64
Q

What is the maxpause definition ?

A

Finds groups of events where the span of time between included events does not exceed a specific value

65
Q

CAn you create a transaction based on multiple fields.

A

Yes

66
Q

Which function should you use with the transaction command to set the maximum total time between the earliest and latest events returned?

A

maxspan

67
Q

What is the Splunk CIM ?

A

Common Information Model provides a methodology to normalize data

68
Q

When should you used the CIM Schema ?

A

When creating Field Extractions, Aliases, Event Types, and Tags.

69
Q

Which datasets can be added to a root dataset to narrow down the search ?

A

A child datasets

70
Q

What are doing required fields in a data models ?

A

They constrains the dataset to only return events that include that field

71
Q

Do the fields used in the data models already have to be extracted before creating the datasets?

A

No

72
Q

Which workflow Action type sends field values to external resources ?

A

POST

73
Q

What we need to use field value data from an event in a Workflow Action ?

A

Wrap the field in dollar signs.

74
Q

Which Workflow Action type directs users to a specified URI ?

A

GET

75
Q

Can Workflow action only be applied to a single field ?

A

No

76
Q

What can do a workflow action ?

A

Direct users to a specified URI.
Execute a secondary search.
Send field values to external sources.

77
Q

Can we add tags to Event Types ?

A

Yes

78
Q

How categorize events based on search terms ?

A

By using event types

79
Q

Can you pipe the results of a macro to other commands ?

A

Yes

80
Q

What is the proper syntax for using a macro named “us_sales”

A

us_sales

81
Q

What allows the search expansion tool ?

A

To see what a macro will expand to before you run a search.

82
Q

Is the search macros must always include an argument ?

A

No

83
Q

What are tags ?

A

The descriptive name for key value pairs

84
Q

Do the event types show up in the fields list ?

A

Yes

85
Q

What allows to categorize events based on search terms ?

A

Events Types

86
Q

Why use field aliases ?

A

To normalise data

87
Q

In the Field Extractor Utility, which button will display events that do not contain extracted field ?

A

Non-Matches

88
Q

What method to extract can be used with the field extractor utility ?

A

Regex & Delimiter

89
Q

Which users can create private Knowledge Objects?

A

Power
User
Admin

90
Q

What the transaction command allows ?

A

To correlate events across multiple sources.

91
Q

What is maxpause for ?

A

Finds groups of events where the span of time between included events does not exceed a specific value

92
Q

Why use stats ?

A

To see results of a calculation, or group events on a field value

93
Q

why use transaction ?

A

To see events correlated together, or grouped by start and end values.

94
Q

By default, what does the fillnull command replace null values ​​with?

A

0

95
Q

Which command is used to create choropleth maps?

A

geom

96
Q

What return the iplocation command ?

A

It returns location information for events that include external IP addresses

97
Q

Which roles can create Private Knowledge Objects?

A

User, Power, Admin

98
Q

When using a .csv file for lookups, the first row in the file represents this.

A

Field names

99
Q

Which is the correct order to use when creating a lookup?

A

Define a lookup table
Define a lookup
Create and automatic lookup

100
Q

What are Field Aliases caracteristics ?

A

Can be referenced by lookup tables.
Are applicable to a specified app context.
Make correlation easier.

101
Q

Can calculate fields use lookup tables ?

A

No

102
Q

What is SVA ?

A

Splunk Validated Architectures (SVAs) are proven reference architectures for stable, efficient and repeatable Splunk deployments.

103
Q

What are Authentication Methods available in Splunk?

A
  • Native Splunk Accounts
  • LDAP
  • SAML
  • Scripted Authentication