Transitioning to Splunk Cloud Flashcards

1
Q

What 5 things does Splunk Cloud Provide?

A

Hosted and supported by Splunk
Enterprise functionality on another’s machine
Reliability
Faster time to value
Cloud First Feature Releases

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Can Splunk Cloud Accommodate both virtual and real infrastructure?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What two components can either be on prem or in the cloud with a cloud deployment?

A

-Universal Forwarder or Heavy Forwarder
-Intermediate UF/HF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the customer responsibilities for the cloud deployment?

A

-Forward the data
-Manage conifgs of sourcetype, index, contextual details
-Admin and coordinate changes: users, retention, configurations, needs associated with Splunk account team or PS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the two usage based license types a cloud customer can use?

A

Ingestion or Infrastructure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Describe ingest based license

A

-capabilities at set cost of ingest
-no additional costs to increase resources, or search activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Describe infrastructure/workload based license

A

Splunk Virtual Core (SVC) units of data processing capacity used for a mix of ingest and search
-capabilities at a set infra size
-no ingest violations
-prioritizing index or search may impact performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the 7 cloud benefits

A

Cloud Support and Ops Provides:
advice/troubleshooting support
Asset management and automated infra deploy
Automated processing and implementation
Regular maintenance and upgrade
Monitor/alert system health/security
IT Ops and security specialists
24/7 NOC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Does Cloud have license pooling or access through the CLI to hosted components?

A

No and there is SH GUI access only

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Can Apps be installed without a vetting process in the Cloud?

A

No, apps should comply to vetting policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What kind of secure forwarding does Cloud offer?

A

Secure SSL and TLS forwarding

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the two Cloud Experiences offered?

A

Classic and Victoria
Victoria - Does not support/need Hybrid search, Inputs data manager, modular or scripted inputs. Uses Admin config Service API for HEC. Has the option to install premium apps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

On Prem vs Cloud access differences

A

Cloud:
- no CLI
- vetted and approved apps permitted
- cant send TCP/UDP directly
- Scripted alerts only supported in approved apps
- License pooling not supported
- HEC enabled on port 443
- APi avail through API self service app or cloud support
- inbound TCP protocol only with SSL connection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Do Splunk Cloud Users have access to the CLI?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Can Direct TCP and syslog inputs be sent directly to Cloud?

A

Not in Cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How is the HEC enabled in the Cloud?

A

Via the ELB on port 443

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What kind of network connection is supported in the cloud?

A

Inbound TCP protocol only with SSL secure connection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are the authentication options for managed splunk cloud?

A

Splunk Native and SAML and LDAP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What are cloud apps installed via and deployed via?

A

Installed via search head and deployed via management app

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

When can Cloud apps be installed through self service?

A

When they are vetted, on splunkbase, or if the customer accepts the liability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

With what release of cloud are most apps self service installations

A

Victoria

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What are the parameters of TCP connections needed for splunk cloud

A

TCP connections need an authorized role, secure token, credentials or certificate validation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is a hybrid search Head?

A

On prem SH initiated search to Cloud, can run searches to combine data from multiple locations, blended search on prem and/or cloud indexers
-not used for premium app SH

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

How does Splunk Version Compatibility work for hybrid searches?

A

On prem SH must have same major.minor version as cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What are the limitations to a hybrid search topology?

A

Can’t search multiple cloud environments and a Cloud SH can not search on prem environments or another cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Can Hybrid SH perform scheduled searches?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

With which method of searching can the search span multiple Cloud and enterprise environments?

A

Federated Search

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Which method of searching requires special syntax of generating commands?

A

Federated Search

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Which type of search, hybrid or federated, supports workload management

A

Federated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Describe Federated Search version control and Architecture

A

Splunk 8.2.x and greater, and supports all search tier management architecture ( like clustering)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

What three admin tasks occur at the source on-prem components?

A

Forwarding of events, input definition/parsing (on prem parsing/masking), problem isolation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Through what cloud component does the cloud admin manage knowledge objects

A

Via splunk cloud search head

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

With what issues would a customer work with Cloud Support?

A

Perf and avail issues
Cloud deployment issues
Config changes and maintenance
Install and manage apps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

What three things does the Cloud Monitoring Console (CMC) Provide?

A

Monitoring and details of topology
Ingestion and Search activity of data
Orientation on overall health and performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

How does the CMC (cloud Monitoring Console) differ from the on prem monitoring console?

A

CMC is pre-configured except for forwarder and workload manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

What is the purpose of the Cloud Migration Assessment App for Splunk?

A

Deploy on Monitoring Console server or SH to perform pre-checks and guidance on migration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

What does the Phased Cloud Migration consist of?

A

Planning, Config and Artifact Migration, data Migration, Data collector Migration, post implementation checks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

What is the average time for a cloud migration?

A

4-8 weeks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

What does the planning phase of cloud migration consist of?

A

Assessing on prem splunk with health checks, gathering configs, recording priorities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

What does the configuration phase of cloud migration consist of?

A

Preparing Cloud with indexes and authentications, configure cloud and IP Based access controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

What does the Artefact Migration phase of the cloud migration consist of?

A

Migrating search artefacts, apps, and workflows (dashboards, apps, alerts, field extractions etc)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

What does the data migration phase of cloud migration consist of?

A

-replicate on prem data input and source types, check CIM, initiate historical data migration
-deploy credential app to forwarders, point data sources to splunk cloud, check inputs for ingest path, timestamp/linebreak/extractions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

How is access to the cloud enabled?

A

With authentication credentials via the user interface
User account must be authenticated by splunk or external identity provider
Authorized by assignment to a splunk role(s)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

What are the three ways of establishing a user account?

A

Native Splunk, LDAP/Active Directory, or SAML

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

What two files maintain the splunk access controls?

A

Authentication.conf
Is the user who they say they are
Authorization.conf
What resources they can access, tasks they can perform, limits are placed on them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

How should customers audit or remove users?

A

Raise a support ticket

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

What capability is needed for user manager roles, and is default for sc admins?

A

Change_authentication capability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

What authentication method is not supported by Cloud?

A

DUO two factor authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

What is a good way to troubleshoot authentication issues?

A

Create a unique Splunk Native admin account`

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

When can authentication replicate?

A

When set up on clustered search heads

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

When using a mix of native Splunk, LDAP, & SAML users, which will take precedence?`

A

Splunk Native

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

What user role is reserved for Cloud Ops?

A

Admin Role

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

What are two additional user roles that Cloud offers?

A

Sc_admin and apps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

What actions are Splunk Cloud Admin allowed to do and why?

A

edit/delete Splunk Native Users
Change time zone, and default app for LDAP/SAML users
Due to limited access in the Cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
55
Q

How are customer Identity providers connected and managed

A

Connected to splunk via internet and managed through splunk web

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
56
Q

Does Splunk Cloud use existing customer configured accounts?

A

Yes, enforces user account a pw policies, and has the ability to use local usernames and pw in splunk with the option to map IdP groups to splunk roles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
57
Q

What must customers do to authenticate users in Cloud using LDAP?

A

-maintain read only, internet accessible LDAP servers
-authenticate and authorize in splunk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
58
Q

When does Splunk cache user data from LDAP?

A

The first time a user logs in AND its reloaded for subsequent logins if an update has been made

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
59
Q

How many Identity Providers (IdP) can a customer using SAML have?

A

Limitation is currently 1 IdP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
60
Q

What type of authentication uses digitally signed XML Certificates from an IdP?

A

SAML

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
61
Q

T/F when mapping SAML Groups to roles, only one group can be mapped to one role

A

False, multiple groups can be mapped to one role

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
62
Q

What are the roles that users can have in splunk Cloud?

A

sc_admin, power, user, apps, can _delete, tokens_auth

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
63
Q

What Cloud user role has the highest number of capabilities?

A

sc_admin

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
64
Q

Which user role can add custom user roles

A

sc_admin

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
65
Q

Which user role can manage apps and has some admin capabilities

A

Apps user role

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
66
Q

Define the can_delete user role

A

Not assigned to any user role or group by default
Can use |delete command to hide data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
67
Q

Define the token_auth user role capabilities

A

Enables users to configure token based authorization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
68
Q

Custom user role authorization is a combination of what 5 things?

A

Role inheritance, capabilities, index access, restrictions and resource usage limits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
69
Q

T/F You can adjust the capabilities of inherited roles

A

False, inherited capabilities or access cannot be disabled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
70
Q

When creating a new user role and assigning indexes, what does selecting the ‘default’ checkbox for an index imply?

A

The index will be automatically searched without a user specifying “index=<index_name>”</index_name>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
71
Q

What are role based restrictions used for when setting up a new user role?

A

Used to restrict the searches a role can use: can set a default time range, indexes fields to filter, field values, concatenation option, and a specific search string to filter results

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
72
Q

What do ‘Resources’ adjust when setting up a new user role?

A

Resources manages the
-role and user search job limit
-role search time window limit
-disk space limit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
73
Q

Can you validate or check on user capabilities in the Cloud?

A

Yes, using REST API, there are searches you can run to get capability info

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
74
Q

What is Workload Management?

A

A rule-based management to allocate compute resources (CPU and Memory) to search, index, and other user workloads

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
75
Q

What is the benefit of workload management?

A

Improve performance, resource availability and productivity:
Separate data ingest from search workload,
Prioritize critical search workloads
Isolate resource heavy searches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
76
Q

What are workload pools?

A

Logical containers which resources (CPU/ mem) are assigned to as part of WLM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
77
Q

What are workload Rules?

A

User defined set of conditions allocate a search to a workload pool automatically or to reduce impact of expensive searches
EX of assigning pool by set criteria: role=security AND search_type=adhoc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
78
Q

What are workload management Admission Rules?

A

Filter searches automatically before execution based on user defined conditions like running searches in a certain time range and searches that use excessive resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
79
Q

Why is “users unable to search” a commonly reported issue>

A

Unrestricted user access may tie up resources impacting access/functionality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
80
Q

Where might resource availability cause performance issues?

A

Data replication and search performance
Disk space/storage availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
81
Q

What measures are taken for disaster recovery in the Cloud?

A

Site awareness - across 3 availability zones
Automatic Index replication of which all copies are searchable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
82
Q

Splunk Cloud Users should be aware of what two indexes?

A

“main” - the default index accepts events not assigned an index
“lastchanceindex” pre-defined in Cloud accepting events sent to a non-existent index

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
83
Q

What two key file types are within an index?

A

rawdata files: raw uncompressed data
tsidx files: Time series index files pointing to raw data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
84
Q

Is it best practice to use index=main when searching?

A

No it is best practice to segregate data into separate indexes and specify your specific index when searching

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
85
Q

What type of indexes are available?

A

Event indexes - unstructured data stored as separate events
Metric indexes - metric data uses less storage and system resources with increased search speed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
86
Q

Describe the process of new and updated indexes are deployed in Cloud.

A

Done through SH UI: changes transferred to Manager Node (MN) which creates a bundle push to files on indexers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
87
Q

How do buckets role from hot to warm to cold in the indexes?

A

Role by exceeding:
-number of buckets
-index size
-event age

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
88
Q

Which index bucket is open for write?

A

Hot bucket

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
89
Q

What 3 options are available as data moves to the frozen state?

A

-purge/delete default unless archive selected
-archive events unsearchable either in splunk or customer managed archive
-thawed, archive data restored

90
Q

Describe Splunk Managed Archive data option

A

Known as Dynamic Data Active Archive: disabled by default and must be purchased in 500GB increments with set retention

91
Q

Describe Customer Managed Archive data option

A

Known as Dynamic Data Self Storage where data is moved to customer managed AWS S3

92
Q

What happens to data accessibility when it is archived?

A

With Active Archive it is easily restored to Splunk Cloud.
With Self Storage data is no longer accessible via Splunk Cloud. Must be re-ingested

93
Q

What happens when DDAA Dynamic Data Active Archive is full?

A

Buckets are deleted

94
Q

Which storage option is best for auditing and tracking historical data/compliance?

A

Dynamic Data Self Storage DDSS as it is a long term option needed for those activities

95
Q

Can data be thawed back into splunk searchable indexes from dynamic data self storage DDSS?

A

No, it has to be thawed in customer environment and data needs to be re-ingested to be restored and searchable in splunk cloud

96
Q

How long is restored dynamic data active archive (DDAA) searchable for?

A

Searchable with 24 hours of being reinstated and searchable for up to 30 days`

97
Q

In what increments can DDAA be purchased?

A

500GB

98
Q

How can you delete an archive?`

A

Logging a support ticket

99
Q

T/F You create the splunk index prior to setting up the AWS S3 bucket name

A

False, bucket must be created prior to creating the self storage location in splunk

100
Q

When using the CMC, what would you check indexing performance for?

A

-missing events
-queue fill issues
-delayed data

101
Q

When using the CMC,what would you check Indexes and Storage dashboard for?

A

-Retention and Sizing
-indexes without events

102
Q

What are several ways missing data can occur (an issue uncovered using the CMC Monitoring Indexes and Storage dashboard)

A

Missing data can occur if:
-ingest volume exceeds index size
-events have aged out or exceeded searchable age limit
-data is masked using the delete command

103
Q

For what purpose do you check the Index Detail Dashboard of the CMC?

A

-ingestion issues
-isolation troubleshooting (through the host source and sourcetype views available)

104
Q

How are TCP connections permitted in Splunk Cloud?

A

With an authorized role, secure token, credentials or certificate validation

105
Q

When would you use a Test server?

A

-standalone dev enviro for test and POC
-replicate cloud indexes/configs to test data collection, parsing and indexed event quality

106
Q

What SPlunk functions would be part of the standalone test server?

A

All functions in a single instance: input, parse, index, and search

107
Q

What is the test server deployment strategy?

A

Test inputs/parsing/events in dev enviro then match prod to dev enviro including versions, apps/configs and index names

108
Q

What type of data collection method monitors local hosts to gather data?

A

Universal forwarder

109
Q

What are the key differences between a universal and heavy forwarder?

A

HF is a full splunk enterprise instance with license and UI, with ability to parse data prior to forwarding it, and can aggregate data from other forwarders to route elsewhere

110
Q

When would you use a HF over a UF?

A

Limit HF to:
-mask/filter data before going to cloud
-manage modular inputs or HEC on prem
-host apps not allowed on cloud

111
Q

How does a user get forwarder credential apps?

A

Customer stacks are commissioned with them preconfigured with forwarding and secure connection settings and installed on a forwarder that outputs data to cloud

112
Q

What does a customer welcome pack include?

A

Stack URL and Forwarder Credential App

113
Q

What does the forwarder credentials app contain?

A

limits.conf
Data transmission limit in limits.conf
outputs.conf
Forwarder output conifgs
SSL secure connection setting

114
Q

Why would you check the forwarder credentials app limits.conf file`

A

A high throughput in limits.conf can overwhelm and indexing tier, block network traffic, or cause events to be dropped so check for:
Missing events, queue fill issues, delayed data

115
Q

How does SSL Compression work in the forwarder credentials app?

A

In the outputs.conf file, it must be enabled on both sides. The compression is good for network bandwidth. It has a cpu penalty

116
Q

Why wouldnt you want unlimited throughput for your forwarders into cloud?

A

May cause higher forwarder resource usage so maintain a limit to control file monitoring and network usage

117
Q

T/F UFs can access the internet without going through a firewall

A

False

118
Q

What is an intermediate UF?

A

A UF or collection of UFs, that relay data to splunk; centralized forwarding of data to cloud

119
Q

Why use an intermediate UF over a UF or HF?

A

-Limits servers with direct access to internet
-reduces overhead of updating firewall rules for each server added or removed

120
Q

Why use multiple forwarder ingestion vs HF or intermediate forwarder?

A

-checkpoints for lossless data collection
-efficient to minimize bandwidth
-built in load balancing, optional encryption, and data compression
-supports multiple inputs and local management

121
Q

What is an intermediate HF?

A

Full enterprise instances as a tier to parse and forward data and manage data ingestion PRIOR to indexing in cloud

122
Q

Why use a Intermediate HF over a UF or intermediate UF?

A

HF can parse and perform indexer tasks in the customer controlled area
-parse and anonymize with or without writing and indexing events
-data can be removed prior to forwarding to Cloud

123
Q

What must be considered when using an intermediate HF in terms of troubleshooting, parsing and ingesting?

A

-troubleshooting could be challenging because hidden intermediate modifies/parses
-parsed data not parsed again in cloud index
-ingested data may differ from original data

124
Q

T/F For both structured and unstructured data, data parsing can occur on UF and HF

A

False, only structure data parsing can occur on both. Unstructured data can not be parsed on a UF

125
Q

How can splunk Cloud get data from TCP or UDP input?

A

Get these inputs on a forwarder because SC cant accept direct Network Inputs or UDP traffic

126
Q

T/F Best practice is to put network inputs on an intermediate forwarder

A

False, Do not put on intermediate. Collect on separate dedicated forwarders

127
Q

Splunk merges what kind of data until it finds a timestamp by default?

A

UDP data

128
Q

How do you get syslog data into splunk cloud?

A

Send to syslog collector writing to a directory structure and monitor the directory using host_segment`

129
Q

How does splunk cloud handle SNMP traps

A

Write traps to file and monitor input. Collect on prem to parse and filter before forwarding

130
Q

When using the CMC Monitoring Forwarder Instance, what do you want to check for?

A

Connection issues: review version and compatibility
Missing/delayed events: forwarder must be connected and sending _internal data

131
Q

What is the CMC Forwarders: Instance dashboard used for?

A

-Drill downs into performance of active/inactive forwarders over time
-Investigate perf and connectivity

132
Q

What is the CMC Forwarders: Deployment dashboard used for?

A

-shows active/inactive forwarder connecting to splunk directly
-shows connectivity

133
Q

When using the CMC Monitoring Forwarder Deployment, what do you want to check for?

A

-Connection and forwarding issues: check when last connected to indexers
-Missing forwarders: check forwarder status
-Checking IDM input rate

134
Q

What is REST API?

A

An application programming interface conformed to REST architectural style used by vendors to expose data and internal management end-points

135
Q

What is a software messenger delivering requests to providers and returning responses to requesting Client?

A

API

136
Q

What is REST?

A

Representational State Transfer - defined constraints for HTTP(s) web services and provides direct interaction with web-based clients

137
Q

What are APIs used for?

A

Expose data and management endpoints providing ability to manipulate outputs or filter results to manage ingestion

138
Q

What are some benefits of using a REST API for ingestion?

A

Manipulate outputs or filter results to manage ingest inflight = reduce data volume and increase ingest speed.
-use less system resources
-minimal impact on performance

139
Q

What API tasks are restricted in Splunk Cloud?

A

Modifying client server configs/components
Restarting deployment or executing debug

140
Q

What are PUSH/PULL requests when using an API?

A

It is how a REST Client reaches endpoints
-PUSH: source attempts to deliver data from streaming source to endpoint
-PULL: streaming or file input source where source continually publishes to an endpoint
- channel opens, Splunk connects to input and ingests the content

141
Q

What API requests does splunk support?

A

GET, POST, DELETE

142
Q

Where can Cloud REST API ingestion Apps and Add-ons be installed?

A

On an IDM in classic Cloud, indexers and/or SH

143
Q

Can non-Splunk Cloud compliant REST API ingestion TAs be used?

A

Yes, if installed on an on-prem HF

144
Q

What type of ingestion reduces the overhead of maintaining machines and network infrastructure?

A

Using REST API

145
Q

What happens to on-prem API inputs.conf files when deployed in cloud?

A

They are encrypted and use a key for security

146
Q

Describe how the API Input TA can be installed

A

Installed as either:
invisible app with a list of data inputs on the configure data collection page
Visible app with UI for managing and configuring inputs

147
Q

What method is used to collect diagnostic data from OS commands?

A

Scripted Inputs

148
Q

What do Scripted inputs do?

A

Schedule a script execution and index the output

149
Q

Why use a scripted input instead of another ingest method

A

It can gather transient data that cannot be collected with monitor or network inputs
Ex: API, message queue, web service, custom transaction

150
Q

What kind of scripts are supported with scripted inputs

A

Shell .sh, Batch .bat, PowerShell .ps1m Python .py

151
Q

Where can scripts be executed from>

A

SPLUNK_HOME/etc/apps/<app_name>/bin
SPLUNK_HOME/etc/system/bin
SPLUNK_HOME/bin/scripts</app_name>

152
Q

In the inputs.conf of a scripted input, what does the the interval = <> mean?

A

Interval is the time period between script executions - default is 60 seconds

153
Q

What is HEC?

A

HTTP Event Collector is a secure and scalable token based HTTP input.
Sends events to splunk without using forwarders

154
Q

What method can you use to ingest info from web browsers, automation scripts or mobile apps?

A

HTTP Event Collector HEC

155
Q

What method of ingestion can facilitate loggin from distributed, multimodal and or legacy environments

A

HEC

156
Q

What are some considerations when using HEC in the cloud?

A

-HEC enabled by default
-Cant change config files because no direct access to indexers
-Doesnt support forwarding to output groups

157
Q

T/F Using HEC will increase infrastructure Overhead

A

False, it will reduce infra overhead

158
Q

How is encryption handled when using HEC?

A

All data is encrypted in transit using TLS 1.2+

159
Q

What port must be used when using HEC?

A

Port 443 and customer cannot change

160
Q

What is the default max content length for HEC in the cloud?

A

1MB

161
Q

How do you enable HEC for Kinesis Firehose or make changes to HEC ?

A

Through filing a support ticket`

162
Q

Can raw payloads be sent to HEC?

A

Yes, HEC allows any arbitrary payloads, not just JSON. But must use channels similar to ACK and events must be bound within a request

163
Q

How are private apps installed on Cloud?

A

Uploaded and vetted via App manager, and vetted via appcert process

164
Q

When do you contact support for Cloud app installs?

A

When app on splunkbase indicates request install or multiple apps need installing`

165
Q

When should you get assisted installation on apps from splunkbase?

A

Apps for hidden components
Bulk installation or planned migration
Scheduling in specific maintenance windows

166
Q

What is considered ‘unsafe practices’ when determining if an app is prohibited

A

Using elevated permissions
Running processes that manipulate OS, file, or security settings

167
Q

What is categorized as prohibited behavior in a Cloud app?

A

Privilege escalations, precedence elevation, using local folder, reverse shells, splunk restart, OS manipulation
Cross site scripting dashboards
Config changed to core splunk ot underlying OS files
Manipulation of OS, Remote Shells, insecure comms and creds storage
Data exfiltration or export

168
Q

What is App Inspect for a Dev Environment?

A

An automated vetting process that could require manual review. Offered two ways outside UI:
-CLI: uses “– coud” tag to validate
-API: uses “– self-service” tag to run package toolkit; can run antivirus checks

169
Q

When do you use Splunk AppInspect API?

A

To validate an app for Cloud prior to install or is preparation for updated settings/configs

170
Q

What do you use the cURL GET command for when using the AppInspect API?

A

Use cURL GET with a splunk username to the Splunk AppInspect API to obtain HTTP auth token

171
Q

How do you submit an app to AppInspect using the API?

A

First use GET request to obtain HTTP token. Then use POST request to submit app to validation endpoint.
Produces a request_id for tracking purposes

172
Q

How do you perform a status check of the AppInspect API?

A

Send a cURL GET request for either a status check or to retrieve a validation report. Both leverage the request_id produced when app was originally submitted

173
Q

Do you need an updated version and build number to vet an upgraded/updated app?

A

Yes otherwise app could fail if build numbers are identical to previous checks

174
Q

When will Splunk Cloud Classic need a restart when uploading apps

A

When app contains static assets, props and transforms

175
Q

Where is a rolling restart required when installing cloud apps?

A

Apps or configs deployed to indexers require rolling restart

176
Q

How is syslog data ingested in the cloud?

A

Logs are collected locally, then forwarded to Splunk Cloud

177
Q

What are the 2 options to collect Syslog data into the CLoud?

A

Sent through an intermediate tier
- Reliable delivery via forwarder
- Requires on prem syslog server for parsing and filtering
Splunk Connect for Syslog (SC4S):
- Containerized Syslog-ng server with data source library
- Filters for ID, Parse and format
- Reduces config and management of syslog servers
- Repeatable concise and prescriptive soln

178
Q

How can you get visibility where collection agents are prohibited?

A

Access streaming data, data off the wire

179
Q

What OS is supported for collecting streaming data?

A

Windows, Mac, Linux

180
Q

What ingest method uses rapid agentless deployment to collect real time data?

A

Streaming data / data off the wire

181
Q

What are the 3 phases of stream data collection?

A

Data Collection points
Streaming data processing
Forwarding data

182
Q

What is Splunk DSP, Data Stream Processor

A

DSP provides real time stream processing to collect, input connectors, process via DSP, and deliver data to splunk via output connectors

183
Q

What is Splunk SPS, Stream Processor Service?

A

Cloud feature using real time stream processing to collect, process and deliver data to splunk
Flexible/scalable, using SVCs

184
Q

What is IDM, Inputs Data Manager?

A

Single hosted data input component in Cloud Classic available for scripted and modular inputs
-IDM is not an app, it hosts input apps

185
Q

How are IDM apps installed?

A

Via support ticket request or uploaded and added by engaging support or PS engineers

186
Q

When is it best practice to use the IDM?

A

Use for Cloud Vendor Services data collection and install cloud based ingestion addons to the IDM

187
Q

Can an IDM accept TCP/UDP inputs like syslog and inputs from HEC

A

No

188
Q

What are some limitations of the IDM

A

Limited on scaling and ingest volume as well as concurrent searching (limit 10)

189
Q

How do you get custom inputs on the IDM?

A

Create modular/scripted inputs and package configs as private app that will need to get vetted then uploaded by support/PS. Manage through IDM login

190
Q

How do you get vendor inputs on the IDM?

A

find prebuilt apps/addons and have PS/support upload to IDM. Configure access controls and manage through IDM login

191
Q

How do you parse and modify data before forwarding?

A

By using a Heavy Forwarder, where you can perform indexer like tasks in the customer controlled environment: parse/mask/remove data before indexing

192
Q

What service is able to parse, modify, and filter data prior to writing events to disk?

A

Streaming processor Service: manage data ingestion prior to indexing in cloud

193
Q

What main issues can impact user experience and information quality

A

Line breaking: lines in event exceed TRUNCATE setting
timestamp parsing: extraction unsuccessful
aggregation: exceeding number of lines per event set in MAX_EVENTS

194
Q

What info is gathered at the input phase

A

Host, sourcetype, source, index

195
Q

What actions occur at the parsing phase?

A

Line breaking, date/time extraction, event level processing, adjust meta fields

196
Q

If you are changing extraction settings in sourcetype, what conf file do you need to update these changes to?

A

props.conf

197
Q

What is an efficient way to break single line events when parsing?

A

Automatic line breaking is used but it is more efficient to set explicitly SHOULD_LINEMERGE = false

198
Q

What is an efficient way to break multi line events when parsing ?

A

While splunk will attempt to find boundaries it is more efficient to set:
BREAK_ONLY_BEFORE_DATE = true (default)
BREAK_ONLY_BEFORE = <regex>
MAX_EVENTS = 256 (default)</regex>

199
Q

What can be used to more efficiently extract date/timestamp in an event?

A

For the timestamp set:
TIME_PREFIX= <regex>
MAX_TIMESTAMP_LOOKAHEAD=<integer>
Specify time format and time zones</integer></regex>

200
Q

How can poor time extraction lead to missing events?

A

Ingested but unavailable in the specified time range
Events rolled off as they are outside retention period
Events not ingested because ‘dates’ beyond allowed range

201
Q

How could you end up with duplicate events if there is a timestamp extraction issue?

A

Splunk assigns a timestamp from a previous event if it cant find one

202
Q

What kind of data prep should be done before mass ingestion?

A

Eval event breaking and date/timestamp settings, then use a test instance onprem and cloud, then redirect to prod

203
Q

What is splunk data preview used for?

A

Creating new sourcetypes and adjusting config settings

204
Q

How can you hide or delete sensitive or identifying data prior to forwarding to Cloud?

A

Use an on prem Heavy Forwarder to modify _raw data

205
Q

Why should you avoid indexing ‘dirty’ data?

A

Minimizes delays, improves search accuracy, data quality, and ingestion time, issues rendering dashboards

206
Q

What can users with the can_delete capability do?

A

Use the |delete command to hide data from searches, but it still consumes disk space

207
Q

For what problem do you NOT contact cloud support?

A

Resizing, License changes, purchases

208
Q

For what problems should you contact cloud support?`

A

Unable to resolve issue or perform problem isolation
Capacity or config changes
Unable to log into cloud

209
Q

What is the difference between a Splunk Support engineer and a Customer Support Engineer?

A

Customer support may troubleshoot, submits support tickets, manages expectations/best practices
Splunk support provides solns to product issues and complex issues and troubleshoots technical problems

210
Q

When troubleshooting what are the 3 likely areas that search can fail?

A

Search request, data retrieval, and manipulation

211
Q

What should you consider when you have issues with a search due to User failures?

A

Check user capabilities, roles, group mappings, access/resource limits

212
Q

At what stages can data ingestion be disrupted?

A

Collection, forwarding, intermediate stage or at the indexing tier

213
Q

What steps do you take if data ingestion is disrupted at the collection and forwarding stages?

A

Check if splunk has access to the data and find if data forwarding is configured via inputs/outputs settings

214
Q

What steps do you take if data ingestion is disrupted at the forwarding stage?

A

Check the output, limits.conf, restricted bandwidth

215
Q

What steps do you take if data ingestion is disrupted at the intermediate forwarding stages?

A

Is it receiving any data, confirm receive and send ports, is it parsing or indexing and parsing data?

216
Q

The cloud monitoring console or CMC is preconfigure so long as customers do what?

A

Enable forwarders and workload management

217
Q

What is Splunk Diag?

A

Diagnostic Screenshot providing insight to onprem splunk instance with current component configs and customization

218
Q

When should you run a splunk diag?

A

Before and after upgrades, creates a backup of configs/settings, faster restore and easier change audit, for splunk cloud support to aid in troubleshooting

219
Q

How do you collect a diag?

A

Run SPLUNK_HOME/bin/splunk diag

220
Q

What is Btool?

A

CLI troubleshooting tool used to audit configs to see what values are being used by splunk

221
Q

What are the limitations of Btool?

A

Only shows merged on-disk configs (at the restart), not the settings Splunk is currently using