Transitioning to Splunk Cloud Flashcards
What 5 things does Splunk Cloud Provide?
Hosted and supported by Splunk
Enterprise functionality on another’s machine
Reliability
Faster time to value
Cloud First Feature Releases
Can Splunk Cloud Accommodate both virtual and real infrastructure?
Yes
What two components can either be on prem or in the cloud with a cloud deployment?
-Universal Forwarder or Heavy Forwarder
-Intermediate UF/HF
What are the customer responsibilities for the cloud deployment?
-Forward the data
-Manage conifgs of sourcetype, index, contextual details
-Admin and coordinate changes: users, retention, configurations, needs associated with Splunk account team or PS
What are the two usage based license types a cloud customer can use?
Ingestion or Infrastructure
Describe ingest based license
-capabilities at set cost of ingest
-no additional costs to increase resources, or search activities
Describe infrastructure/workload based license
Splunk Virtual Core (SVC) units of data processing capacity used for a mix of ingest and search
-capabilities at a set infra size
-no ingest violations
-prioritizing index or search may impact performance
What are the 7 cloud benefits
Cloud Support and Ops Provides:
advice/troubleshooting support
Asset management and automated infra deploy
Automated processing and implementation
Regular maintenance and upgrade
Monitor/alert system health/security
IT Ops and security specialists
24/7 NOC
Does Cloud have license pooling or access through the CLI to hosted components?
No and there is SH GUI access only
Can Apps be installed without a vetting process in the Cloud?
No, apps should comply to vetting policy
What kind of secure forwarding does Cloud offer?
Secure SSL and TLS forwarding
What are the two Cloud Experiences offered?
Classic and Victoria
Victoria - Does not support/need Hybrid search, Inputs data manager, modular or scripted inputs. Uses Admin config Service API for HEC. Has the option to install premium apps
On Prem vs Cloud access differences
Cloud:
- no CLI
- vetted and approved apps permitted
- cant send TCP/UDP directly
- Scripted alerts only supported in approved apps
- License pooling not supported
- HEC enabled on port 443
- APi avail through API self service app or cloud support
- inbound TCP protocol only with SSL connection
Do Splunk Cloud Users have access to the CLI?
No
Can Direct TCP and syslog inputs be sent directly to Cloud?
Not in Cloud
How is the HEC enabled in the Cloud?
Via the ELB on port 443
What kind of network connection is supported in the cloud?
Inbound TCP protocol only with SSL secure connection
What are the authentication options for managed splunk cloud?
Splunk Native and SAML and LDAP
What are cloud apps installed via and deployed via?
Installed via search head and deployed via management app
When can Cloud apps be installed through self service?
When they are vetted, on splunkbase, or if the customer accepts the liability
With what release of cloud are most apps self service installations
Victoria
What are the parameters of TCP connections needed for splunk cloud
TCP connections need an authorized role, secure token, credentials or certificate validation
What is a hybrid search Head?
On prem SH initiated search to Cloud, can run searches to combine data from multiple locations, blended search on prem and/or cloud indexers
-not used for premium app SH
How does Splunk Version Compatibility work for hybrid searches?
On prem SH must have same major.minor version as cloud