Splunk licensing is based …
on the amount of data indexed.
The daily license quote includes the full size of data flowing through the ___, but not the disk storage.
parsing pipeline
Replicated data, summary indexes, internal logs, and metadata ___ count towards license quota.
does not
What are the Splunk license options?
Enterprise Free Trial Splunk for industrial IoT license Forward Dev/test license
Enterprise
o Can be bought for any indexing volume
o Enables all Splunk features including clustering and distributed search
o No enforcement. Users can still search after license violation
o Licenses can be stacked
Free
o Includes 500mb/day indexing for life
o Disabled features include clustering, authentication, distributed search, alerting and deployment management
Trial
o Full Splunk features for 60 days
o After 60 says it automatically becomes free license
o Max 500mb a day
o Sales Trial license can be provided for customised license
Splunk for industrial IoT
o Not stackable
o Access to Splunk enterprise and a select premium Splunk apps
Forward
o Allows forwarding of unlimited data
o Cannot be used for indexing
o No need to purchase separately
o Universal forwards automatically apply forwarder license
o Heavy forwarder must be converted to Forwarder License group
Dev/Test
o For running Splunk in Non Prod environments
o Cannot be used in distributed environment
o Not stackable
o Can be used for Splunk App development
What are the license warnings and violations?
How do you monitor for license warnings?
How do you handle license violations?
How is a search performed?
How does Splunk retrieve data?
* Bloom filter – calculate bloom filter on base search and compare against buckets bloom filter
What is a bloom filter?
What is a search artifact?
What is a distributed search?
Distributed search separates search management and presentation layer from indexing and search retrieval layer
How does a distributed search work?
What are search peers?
What is a knowledge bundle?
Where is the location of a knowledge bundle?
How does does a knowledge bundle get replicated?
* Delta – changes since last full bundle push
What are the four replication policies?