QUESTIONS AND CORRECT
DETAILED ANSWERS (VERIFIED
ANSWERS) |ALREADY GRADED A+
What is Splunk? - Answer- Aggregate, analyze and get answers from your machine
data
What Data? - Answer- Index any data from any source
3 main components of Splunk - Answer- Search head, indexer, forwarder
How is Splunk deployed? - Answer- Splunk Enterprise, Splunk Cloud, Splunk Light
Splunk Enterprise - Answer- installed and administered on prem
Splunk Cloud - Answer- Splunk Ent as a scalable service, no infrastructure required
What are splunk Apps? (4) - Answer- -Designed to address a wide variety of use cases
and extend the power of splunk
-Collections of files containing data inputs, UI elements, and/or knowledge objects
-Allows for multiple workspaces for different use cases/user roles to co-exist on a single
deployment
-1000+ ready-made apps available on splunkbase.com or admins build their own
Splunk Enhanced solutions? (3) - Answer- ITSI, ES, UBA
How many roles are there is Splunk? - Answer- 3 - User, Power, Admin
What is the search and reporting app? (3) - Answer- -provides a default interface for
searching and analyzing data
-enables you to create knowledge objects, reports, dashboards
-access by selecting the Search and Reporting button on the home app or from app
view.. select Apps>Search&Reporting
Data Summary? - Answer- Host, Source, Sourcetypes
Host - Answer- Unique identifier of where the events originated (host name, IP Address)
Source - Answer- Name of file, stream or other input
Sourcetype - Answer- Specific data type or data format
, Indexer - Answer- Processes machine data, storing the results in indexes as events,
enabling fast search and analysis
What happens as the indexer indexes data? - Answer- It creates a number of files
organized into sets of directories by age
What does the indexer contain? - Answer- raw (compressed) data, indexes(points to
raw data)
Search head (5) - Answer- -Allows users to use the Splunk search language to search
the index data.
-Distribute requests to the indexers which perform the actual searches on the data.
Search heads
-Consolidate the results and extracts field value pairs from the events to the user
-Knowledge objects on the search heads can be created to extract additional fields and
transform the data without changing the underlying index data
-Provide tools to enhance the search experience such as reports, dashboards, and
visualizations
Forwarders (4) - Answer- -Consume and send data to the index
-Require minimal resources and have little impact on performance
-Usually resides on machine where data originates
-Primary way data is supplied for indexing
Less common Splunk Components - Answer- Deployment Server, Cluster Master,
License Master
Types of Deployments (3) - Answer- -Standalone-Single Server
-Basic-Splunk Server
-Multi-Instance
Standalone-Single Server (deployment) - Answer- 1 instance, for testing, POC, personal
use and learning. Default settings
Basic-Splunk Server (deployment) - Answer- Manage the deployment of forwarder
configurations
Where are forwarders installed on a basic deployment? - Answer- At the data source
(usually production servers)
Basic Deployment Requirements (3) - Answer- -less than 20GB
-Less than 20 users
-small amount of forwarders
Multi Instance (deployment) (2) - Answer- -Increases indexing and searching capacity