B&D are correct as per the System Admin official Course:
Preconfigured Indexes list:
Index name Purpose
_internal To index Splunk’s own logs and metrics
_audit To store Splunk audit trails and other optional auditing information
_introspection To track system performance, Splunk resource usage data, and provide Monitoring Console (MC) with performance data
_thefishbucket To contain checkpoint information for file monitoring inputs
summary Default index for summary indexing system
main Default index for inputs; located in the defaultdb directory
B&D, System admin course, page 171.
Preconfigured Indexes:
_internal To index Splunk’s own logs and metrics
_audit To store Splunk audit trails and other optional auditing information
_introspection To track system performance, Splunk resource usage data,
and provide Monitoring Console (MC) with performance data
_thefishbucket To contain checkpoint information for file monitoring inputs
summary Default index for summary indexing system
main Default index for inputs; located in the defaultdb directory
Index name Purpose
_internal To index Splunk’s own logs and metrics
_audit To store Splunk audit trails and other optional
auditing information
_introspection To track system performance, Splunk resource usage data,
and provide Monitoring Console (MC) with performance data
_thefishbucket To contain checkpoint information for file monitoring inputs
summary Default index for summary indexing system
main Default index for inputs; located in the defaultdb directory
B and D
_internal
To index Splunk’s own logs and metrics
_audit
To store Splunk audit trails and other optional auditing information
_introspection
To track system performance, Splunk resource usage data, and provide Monitoring Console (MC) with performance data
_thefishbucket
To contain checkpoint information for file monitoring inputs
summary
Default index for summary indexing system
main
Default index for inputs; located in the defaultdb directory
B, D are the correct answer. After installing Splunk 8.2 on my local machine I checked the default indexes.conf, and there is the fishbucket index configured.
Agreed B and D. Quoting the Splunk Reference URL https://www.splunk.com/en_us/blog/tips-and-tricks/what-is-this-fishbucket-thing.html
"t’s time for a little Indexing 101. If you look in the directory where your Splunk datastore resides (default location /opt/splunk/var/lib/splunk) you will find a directory called fishbucket. This index is not really intended for normal humans to investigate, more just Splunk engineers trying to decipher file input issues. It contains seek pointers and CRCs for the files you are indexing, so splunkd can tell if it has read them already. To see what’s there, try searching for “index=_thefishbucket”. Events look something like this:"
I believe the only answer is B.
The other preconfigured indexes are:
main: The default Splunk Enterprise index. All processed external data is stored here unless otherwise specified.
_internal: This index includes Splunk Enterprise internal logs.
_metrics: This index contains Splunk Enterprise internal data, stored in the form of metric data points.
_audit: Events from the file system change monitor, auditing, and all user search history.
_introspection: This index provides data about the Splunk Enterprise instance and environment .
https://docs.splunk.com/Documentation/Splunk/8.2.2/Indexer/Aboutmanagingindexes
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
ChantreyC
Highly Voted 4 years, 1 month agoSandy_1988
Highly Voted 4 years, 1 month ago3bd8ac0
Most Recent 1 week, 5 days ago3bd8ac0
2 weeks, 4 days agoMonicaKarim
1 month ago65aab2c
4 months, 1 week agosamsam5136431
7 months, 2 weeks agoallahsal
11 months, 4 weeks agoHNaka
1 year agoadamsca
1 year, 10 months agooswaldek
2 years, 2 months agoSteve2610
2 years, 6 months agohuu_nguyen
3 years agoApis
3 years, 1 month agolilsem
3 years, 5 months agoucsdmiami2020
3 years, 4 months agofuriousjase
3 years, 5 months agoSasnycoN
3 years, 2 months agorodrigok
3 years, 10 months ago