Module 4: Getting Data In Flashcards

1
Q

Add Data: Monitor option

A

Monitor files, directories, HTTP events, TCP/UDP, Scripts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Add Data: Forward option

A

Receive data from external forwarders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

App context

A

Tells splunk which app to apply source type to.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Reasons to have separate indexes

A

Faster searches (narrower searches)
Limit access by user role
Set different retention policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Main input source

A

Forwarders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly