Module 1: Splunk Cloud Overview Flashcards

1
Q

What are the three core components of Splunk?

A
  • Indexer
  • Search head
  • Universal forwarder
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is an indexer?

A

receives, parses and stores machine data in files. Serves search requests

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a search head?

A

web interface for the users. Dispatch searches to indexe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a universal forwarder?

A

collects data from the clients and forwards for indexing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the features of a License Master?

A

o manages Splunk licenses.
o Other Splunk components are license slaves
o Can be a co-located with other components such as Monitoring console
o Licenses can be managed through Splunk Web

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the features of a Deployment Server?

A

o Managed configuration files on the deployment clients
o Maintains configuration is serverclass.conf
o Alternative such as ansible / puppet can be used
o Configuration files are packaged as apps
o Deployment clients periodically poll Deployment server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the features of a Cluster master?

A

o Managed the indexer cluster
o There is only one cluster master
o Maintains data bucket status and handles replication
o Distributes configuration files and apps to Cluster members

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the features of a Search head deployer?

A

o Distributes apps and configuration files to search head cluster members
o Keeps the files in $SPLUNK_HOME/etc/shd-apps
o Cannot run on the same instance as a cluster member

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the features of a Monitoring console?

A

o A Web apps that helps to monitor the system health
o Rich set of charts and stats
o One-stop-shop to monitor everything
o Only admins have access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the features of a Heavy Forwarder?

A

o Can parse data before forwarding to indexer
o Full Splunk enterprise binary with distributed search disabled
o Can also index data locally
o Smaller footprint compared to indexer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly