definitions Flashcards

1
Q

What are fields?

A

building blocks of a Splunk search

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are field aliases?

A

normalizing data by assigning an alternate name to existing fields in your data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are field extractions?

A

values are contained in a field at search time, but can also be manually extracted with the help of regex or delimiters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are calculated fields?

A

perform calculations based on the values of existing fields

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are lookups?

A

used to add additional fields and values that are not contained in your data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are event types?

A
  • used to save a search that you use often
  • user-defined field that represents a category of events
  • can be used to normalize field names, tags and field extractions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are tags?

A

saved key-value pairs (labels for your data)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are workflow actions?

A

provide links within your data that interact with external resources or narrow your search (HTTP GET, HTTP POST, secondary search)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are reports?

A

searches you run repeatedly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are alerts?

A

searches you run repeatedly (scheduled or real-time), that send notifications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are macros?

A

search strings or portions of search strings that can be reused in multiple places

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are data models?

A
  • hierarchically structured datasets that can consist of three types: events, searches, transactions
  • can be used in pivot
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a saved search?

A
  • a search that a user makes available for later use
  • a type of knowledge object
  • reports, alerts, scheduled searches are types of saved searches
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a knowledge object?

A
  • user-defined entity that enriches the existing data
  • tool used to discover and analyze various aspects of data
  • fields, field extractions, saved searches, event types, tags, field aliases, lookups, workflow actions, reports, alerts, data models
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the CIM?

A
  • Common Information Model
  • 22 pre-configured data models
  • fields names and tags
  • least common denominator of a domain of interest
  • used to normalize your data to match a common standard
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are transforming commands?

A
  • massages raw data into a data table
  • transform specified cell values for each event into numerical values that can be used for statistical purposes
  • required to transform search results into visualizations
  • top, rare, chart, timechart, stats, geostats,…
17
Q

What are the three search modes?

A

Fast: quick but not detailed (no contents for interesting fields)
Smart (default): combination of fast & verbose
Verbose: slow but detailed (returns all possible field and event data)

18
Q

What is a data series?

A

a sequence of related data points that are plotted in a visualization

19
Q

What are expressions?

A

produce a value and can be composed by literals, functions, fields parameters, comparisons and other expressions

20
Q

Which are the Splunk CIM Add-On Data Models?

A

Alerts
Application State
Authentication
Change Analysis
CIM Validation (S.o.S)
Databases
Email
Interprocess Messaging
Intrusion Detection
Inventory
Java Virtual Machines (JVM)
Malware
Network Traffic
Performance
Splunk Audit Logs
Ticket Management
Updates
Vulnerabilities
Web

21
Q

What is the order of processing for knowledge objects at search time?

A

(first to last)
–> field extractions
–> field aliases
–> calculated fields
–> lookups
–> event types
–> tags