System Admin Flashcards

1
Q

Install, configure and manage components, manage apps, splunk licensing, indexes, users and authentication, configuratin files, alerts monitor MC and system health.

A

System Administration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Primarily responsible for data onboarding and management efforts that includes new data sources, newly ingested data sources, manage inputs for UFs/HFs to capture data, parsing event line breaking timestamp extraction, manage conf files and deploy changes to production

A

Data Administration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

collect data and send it to splunk servers

A

Forwarders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q
  • Allow users to submit search request using SPL
  • Distribute search request to the indexers
  • Consolidate results and render visualization results
A

Searching

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
  • Reside on a dedicated machines
  • Recieve index and store incoming data from forwarders
  • Search data in response to request received from search heads
A

Indexing Parsing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
  • Splunk instances that monitor configured inputs and forward data to the index
  • Requires minimal resources and typically installed on the machines that produce data
A

Inputs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

splunkd, splunk web, web app-server proxy and kv-s tore

A

8089 8000 8065 8191

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Provides both a search and management front-end for splunkd process

A

Splunk Web

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Is the phyton server to listen on

A

8065

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Splunk admin only app used to monitor and investigate splunk performance, resource, usage and more

A

MC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Provides a number of preconfigured platform alerts

A

MC Alerts Setup

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

is a trial Enterprise license of varying size and duration

A

Sales trial License

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
  • Disables alerts, authentication, clustering distributed search summarization and forwarding to non splunk servers.
  • Allows 500 MB/day of indexing and forwarding to other splunk instances.
A

Free License

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
  • Set the server up as a heavy forwarder
  • Applies to non indexing forwarders
  • Allows authentication but not indexing
A

Forwarder License

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Allow licenses to be subdivided and assigned to a group of indexers

A

Pools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly