Forwarding Data Flashcards

1
Q

Can universal forwarder index data

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What heavy forwarder can do

A

Heavy forwarder allows you to perform all if other tasks that indexer is capable of including indexing, data routing and transformation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Setting up Geary forwarder process

A

Install full Splunk Enerprise
Enable forwarding on the instance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Ways to setup forwarding

A

Splunk Web
Splunk CLI
Create and configure outputs conf

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Setup heavy forwarder process

A

Settings > Forwarding and receiving > Add new > Configure forwarding > ip of receiving splunk instance and receiving port

For load balancing can add multiple hosts as comma separated list

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Configure heavy forwarder to index and forward data

A

Settings > Forwarding and Receiving > Forwarding defaults

Additional configuration from outputs.conf

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Setup heavy forwarding via CLI

A

$SPLUNK_HOME/bin/

splunk enable app SplunkForwarder -auth username:password

Restart splunk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Start forwarding from CLI

A

$SPLUNK_HOME/bin/

splunk add forward-server host:port -auth username:password

How well did you know this?
1
Not at all
2
3
4
5
Perfectly