Cribl User CCOE Flashcards
Data without a particular format can be processed by Stream
True
Cribl Stream is limited to ONLY processing JSON, CSV, Key-Value formats
False
What are numeric respresentations of data measured over intervals of time?
Metrics
Cribl Stream can process a wide variety of data and export it to RAW or JSON format.
True
Metrics are the smallest unit of data.
False
____ are a type of data that provides Cribl Stream with inputs for learning about an IT environment.
Logs
The observability lake does not replace existing observability and security solutions - it augments them.
True
Cribl Stream can work with a wide variety of agents.
True
(Select all that apply) What are some common data tools?
Data Lakes and Object Storage, Agents, SIEM
The three V’s of data are Volume, Value, and Variety
True
In a distributed environment, the Leader Node is used to configure each Worker Node.
True
It is best practice to install the Cribl application in the /opt directory
True
Cribl Stream must be installed as a privileged user
False
It is best practice to create a Cribl user to install Cribl
True
Cribl Stream is a Free download from the Crible website
True
Port 9001 must be open in order to deploy Cribl Stream
False, Port 9000 is the correct port
What default port is used to deploy a distributed Cribl Stream environment?
Port 4200
Crible Stream uses a different binary to install the workers?
False
Cribl Stream supports the ability to use systemd or initd to start on boot
True
Git is optional when installing Cribl Stream when in Distributed Mode.
False
Cribl Leader Node
Manages both Worker Nodes and Edge Nodes by sending configuration information
Cribl Stream
Uses Worker Nodes to process data. A Worker Group is a group of nodes with the same configuration.
Cribl Edge
Uses Edge Nodes to gather data. A fleet or sub fleet is a group Edge Nodes that are of the same type or collecting the same kind of data.
Cribl Stream: Sources
Stream supports both push and pull
Push-based: sources that send sata to Stream
Pull-based: Sources that fetches data from
Collectors: Ability to fetch data from local or remote sources on a schedule