what are considered hosts by splunk ?
computers, sensors, virtual machines, web servers, network devices, databases
hosts usually generate a variety of data including
fault
configuration
accounting
performance
security
system logs
application logs
metrics
tickets
where can splunk index data from ?
what are the processing components of splunk ?
indexers
forwarders
search heads
what are the management components of splunk ?
what can a search head do once connected ?
what are some details about splunk forwarders ?
forwarders are generally installed on host machines to collect source data and send to splunk
forwarders are the primary way to send data to splunk for indexing
what are the two types of splunk forwarders ?
-Universal forwarder
Heavy forwarders
- configured from full splunk enterprise installation
- can parse and filter before forwarding
what is a splunk component that resides on machines originating data ?
forwarder
what is the difference between universal and heavy forwarders
heavy forwarders can parse data
how does splunk data flow initially ?
data from hosts —> Indexer —-> indexes on disk
what is an indexer in splunk ?
An indexer or search peer is a Splunk enterprise instance that processes and writes data into repositories as events
what is processing in regards to splunk?
what is thawed data in splunk ?
thawed data in splunk is when you are bringing data out of the archive
what is an Indexer cluster ?
what is a splunk component that transforms raw data into events?
indexer and heavy forwarders are the splunk components that transform raw data into events
what are some of the details regarding search heads
Can create fields and other knowledge objects such as
- reports
- alerts
- visualizations
- dashboards
what are some details regarding the search head cluster ?
what are some details of the configuration deployment server?
what is the forwarder manager for Splunk ?
provides a way to configure deployment servers and monitor updates
what is the license manager in Splunk ?
Hosts licenses and assigns license volume to other splunk components in a distributed deployment
License meter runs during indexing
License types
- Volume based
- Infrastructure based
- Access to splunk features
what is the monitoring console in Splunk ?
Used to view topology and performance information.
what are the three main out of the box roles in Splunk ?
User
Power
Admin
what are some of the default app examples ?
home app
search app