Introducing Splunk Flashcards

1
Q

What are Splunk apps (1)

A

Collection of files containing data inputs, UI elements, knowledge objects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are Splunk apps (2)

A

Apps allow different workspaces for specific use cases or user roles to co-exist on same Splunk server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Search and reporting app

A

Default interface for searching and analyzing data
Allows user to create knowledge objects, reports, dashboards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Host

A

Unique identifier where events originated (host name, ip, etc)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Source

A

Name of stream, file or other input

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Sourcetype

A

Specific data type or data format. Parser to parse known log format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly