Splunk Basics Flashcards

(33 cards)

1
Q

After installation what does a machine contain?

A

Splunk Instance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What can a Splunk Instance be configured into?

A

One or more Splunk Components

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Types of processing components

A

Indexers
Forwarders
Search Heads

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Types of management components

A

Deployment Server
Indexer Cluster manager
Serach head cluster deployer
Licesne Manager
Monitor console

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Forwarder(s)

A

Install on host
Configure to collect and send data to splunk indexer
Universal Forwarder- main function to collect and send data.
Heavy Forwarder - Can parse and make changes before forwarding.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Indexer

A

Splits the data to fields and parses, can also assign meta data.
Writes the data to repositories known as INDEXES.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Buckets

A

repositories containing files with indexed data.
When data is written it is to a HOT bucket.
When searching data it can be to the hot, warm, and cold bucket.
Archived buckets are frozen and need to be thawed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Indexer Cluster

A

Group indexers together to provide data replication
Cluster manager manages the cluster

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Bucket definistions

A

Hot - Data that is actively being written to (Can have multiple per index)
Warm - When a hot bucket fills up or when Splunk is restarted it rolls to warm.
Cold - When index size limit is reached warm rolls to cold.
Frozen- After aging out data is rolled to frozen. Not searchable. Default data that is deleted is frozen, but you can choose to archive.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Search Heads

A

Search management and presentation from indexers
Serach Head cluster - group of search heads with identical config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Cluster Captain

A

One of the search heads in cluster
Coordiantes search jobs and replication
Failover management, if captain fails another is auto elected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Search Head Cluster Deployer

A

Pushes configuration bundles (apps and settings) to search heads

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Deployment Server

A

Distributes content, configuration, apps to other groups of Splunk Instances (Deployment clients(Indexers, search heads, forwarders not in cluster))
Mostly used to distribute apps to forwarders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Forwarder management

A

a GUI that manages your deployment server.
Accessible through Web UI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Splunk Licensing

A

Volume based - volume of data indexed per day
Infrastructure based - Recourse (vCPU) usage across deployment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

license manager

A

Host licenses and assigns license volume to Splunk components (License peers)
Can create license pools from licenses added together (Stacks)

17
Q

License Peers

A

Any splunk instance (indexer, heavy forwarder, etc) that uses a license and reports usage to license master

18
Q

License Master

A

Manages and enforces the license

19
Q

Monitoring Console

A

Used to view topology and performance information about deployment
Monitoring dashboards use data from splunk internal logs

20
Q

Splunk Enterprise Installation Requirements

A

Default OS - Windows, Linux, and MacOS
Machine types: laptop, server, VM, container
Packages: Trial license, universal forwarder package
Need Splunk account

21
Q

Limits on Trial License

A

Up to 500 MB / day
60 days for features like authentication, alerting, indexing clustering

22
Q

Splunk Web UI

A

Primary way to use administer Splunk
Splunk CLI
Configuration files (other 2 ways change these, but you can directly edit them aswell)

23
Q

Splunk User Roles

A

User - Run searches, use dashboards & reports, save personal searches/ reports
Power - Can create alerts, tag events, use workflow actions, reassign knowledge objects they own
Admin - Edit system settings, manage indexes and data inputs, manage users and roles, install and manage apps, manage KO across all users

24
Q

Knowledge objects

A

Reports, Alerts, Dashboards, data models, etc

25
Access Splunk Web UI
Default Splunk Enterprise port is 8000
26
Splunk Apps
custom solutions that allow extended functionality
27
Default Apps
Home App - starting point for navigating splunk, list available apps, and offers help resources Search and reporting App - Main interface to search, report, dashboards, etc.
28
Where else can you download apps?
https://splunkbase.splunk.com
29
The Home App
Splunk bar (Top of page): Splunk Logo - access Splunk Home Account Menu - Account settings and prefrences Settings - Configuration, administration, monitoring Messages - system errors Activity - Shortcut to jobs, triggered alerts Apps Panel (List of available apps) Explore Splunk panel (Links to useful info)
30
Account Menu
Account Settings (name, email, password) Preferences: Global - Time zone, default application, theme SPL Editor - Configure search assistance, choose theme, add line numbers
31
Settings Menu
Knowledge - Searches reports and alerts, data models, event types, tags, fields, lookups, UI, Alert actions, advanced search, and all configs (Create and manage KO) System - System settings, licensing, restart splunk from GUI Data - create indexes and configure data inputs, config data forwarding and receiving Distributed environment - Forwarder management, indexer clustering Users and authentication - Roles, users, tokens, password management, authentication methods Monitoring Console
32
Search modes
Fast - Fastest with least detail or fields Smart - Balanced speed and detail (if you use a transforming search (stats, chart, timechart) it behaves as fast, if you use non transforming it behaves as verbose Verbose - Slowest but most complete
33
Data Summary tab shows what options?
Hosts Sourcetypes Sources