29 October 2020

#Splunk

Splunk
What is Load Balancer (LB)?
What is Heavy forward (HF)?
What are Splunk Enhanced Solutions?
What is Splunk ITSI?
What is the use of hosts, source and sourcetype tab?
What is the use of Events tab?
What is raw data?
What is cluster master?
What is Search peers?
What is Traditional Index Clusters and Non-replicating Index Clusters?
What is ClusterMaster?
What is Input phase,Parsing phase and Indexing phase?
What is License Meter?
What is Splunk Management Port?
What is Splunk Web Port?
What is Splunk Network port?
What is Splunk Index Replication Port?
What is Splunk Indexing Port?
What is KV store?
What is Splunk agent?
What is search head pooling?
What is search head clustering?
What is Universal forwarder?
What is the difference between Universal forwarder and Heavyweight forwarder?
What is the Life cycle of splunk? (Hot, Warm, Colld, Frozen)
What is Real-time dashboards?
What is Dynamic form-based dashboards?
What is Fast mode?
What is Smart mode?
What is Verbose mode?
What is the use of Abstract command?
What is the use of Erex command?
What is the use of Addtotals command?
What is the use of Accum command?
What is the use of Filldown command?
What is the use of Typer command?
What is the use of Rename command?
What is the use of Anomalies command?
What is license violation?
What is the general expression for extracting IP address from logs?
What purpose does the Time Zone property serve in Splunk?
What is Sourcetype?
What is the need for Splunk Alert? Specify the type of options you get while setting up Splunk Alerts.
What is the configuration files precedence in Splunk?
What is System Local Directory?
What is App Local Directories?
What is App Default Directories?
What is System Default Directory?
What is Replication Factor?
What are the components of Splunk?
What is Splunk Indexer? What are the stages of Splunk Indexing?
What is a Splunk Forwarder? What are the types of Splunk Forwarders?
What are the types of Splunk Licenses?
What is Splunk App?
What are the features not available in Splunk Free?
What happens if the License Master is unreachable?
What is Summary Index in Splunk?
What is Splunk DB Connect?
What are the different types of Splunk dashboards?
What are Buckets? Explain Splunk Bucket Lifecycle.
What is the difference between stats and eventstats commands?
What do Splunk Licenses specify?
What is the command for restarting Splunk web server?
What is the command for restarting Splunk Daemon?
What is the command used to check the running Splunk processes on Unix/Linux?
What is the command used for enabling Splunk to boot start?
What is Source Type in Splunk?
What is Btool?/How will you troubleshoot Splunk configuration files?
What is the difference between Splunk App and Splunk Add-on?
What is .conf files precedence in Splunk?
What is Fishbucket? What is Fishbucket Index?
What is Dispatch Directory?
What is the difference between Search Head Pooling and Search Head Clustering?
What is MapReduce algorithm?
What is the difference between Splunk SDK and Splunk Framework?
What are diffrence between splunk app and splunk add-on?
what are most important configuration files of splunk OR can you tell name of few important configuration files in splunk?
What are Splunk buckets? Explain the bucket lifecycle?
What are the common port numbers used by Splunk?
What are the components of Splunk? Explain Splunk architecture?
What are the features that are not available in Splunk free?
What Are Types Of Splunk Licenses?
What command is used to enable and disable Splunk to boot start?
What do you understand by Splunk Administration? What is the latest version of the tool Splunk?
What is a syslog server?
What is bucket ? How data ages in Splunk ?
What is CIM and what is it used for?
What is command for restarting just the splunk daemon?
What is crontab?
What is indexes.conf?
What is inputs.conf?
What is props.conf?
What is server.conf?
What is Splunk Administration?
What is Splunk cloud administration?
What is Splunk?
What is the difference between Search time and Index time field extractions?
What is the eval command?
What is the null queue?
What is the source type in Splunk?
What is the use of DB Connect in Splunk?
What is the use of License Master in Splunk?
What is the use of sort command?
What is the use of the deployment server in Splunk administration?
What is transforms.conf?
What is use of Time Zone property in Splunk and when it is required?
What will you do in case License Master is unreachable?
What would you use to edit contents of the file in Linux? Describe some of the important commands mode in vi editor?
What would you use to view contents of a large file? How to copy/remove file? How to look for help on a Linux?
What are types of field extraction. How to mask a data in either of case
What do you mean by roles based access control?
What is null queue
What are the types of search modes supported in splunk?
What is difference between source & source type
What is join command and what are various flavours of join command.
What is Splunk? Why Splunk is used for analysing machine data?
What are the benefits of getting data using forwarders?
What happens if License master is unreachable?
What is the command to get list of configuration files in Splunk?
What is the command to stop and start Splunk service?
What is index bucket? What are all stages of buckets?
What are important configuration files in Splunk?
What is global file precedence in Splunk?
What is difference between stats and timechart command?
What is lookup command?
What is the role of Deployment server?
What are the default fields in Splunk?
What is Search Factor (SF)
What is the difference between Splunk apps and add-ons?
What restrict to find data?
What happens when to increase the data limitation?
What is used for building a ranking?
What is used to process huge data sets?
What is used to track internally?
what is the use of DB connect?
What is single-instance storage?
What is used for collecting the logs?
What is known as a central resource for searching?
What is used to conduct the group of field details?
What is Occasion management?
What is Transaction
What is splunk latest version
What is splunk Success Framework?
What is pivot?
Types Of Splunk Forwarder?
How to trouble shooting Splunk errors in splunk
Rollback your aplunk web configuration bundle to previous version
Mention the use of the Dedup command of Splunk?
List some of the features that is lagging in Splunkfree?
If I want to add folder access logs from a windows machine to Splunk, how do I do it?
If you wish to use a free version of Splunk, which features are lacking?
How Does Splunk Work?
How Is Splunk Deployed?
How many type data input supported by Splunk?
How can you troubleshoot Splunk performance issues?
How to know when Splunk has completed indexing a log file?
How can you add folder access logs from a Windows machine to Splunk?
How does Splunk avoid duplicate indexing of logs?
How to troubleshoot Splunk performance issues?
How does Splunk determine 1 day, from a licensing perspective?
How are Forwarder Licenses purchased?
How to disable Splunk boot-start?
How to reset Splunk Admin password?
How to disable Splunk Launch Message?
How to clear Splunk Search History?
How do I exclude some events from being indexed by Splunk?
How to set the default search time in Splunk 6?
How would you handle/troubleshoot Splunk License Violation Warning?
How can we extract fields?
How do you reset Splunk Admin Password?
How does Splunk help in the Organization?
How is a career path in Splunk Administration?
How many types of Splunk forwarders are there?
How Splunk helps the enterprise?
How to reset splunk password?
How do you log in to a remote Unix box using ssh?
How you will uncompressed the file? How to install Splunk/app using the Splunk Enterprise .tgz file
How to use btool for splunk conf file approach
How to turn down a peer without affecting any other peer of cluster?
How to show which deployment server in configured to pull data from?
How to see all the license pool active in our Splunk environment?
How do we convert unix time into string and string back to unix time format
How do we find total number of host or source type reporting splunk instance. Report should consider host across the cluster
How can you exclude some events from being indexed in Splunk?
How do we sync and deploy configurational files and updates across multiple deployment servers in a large multi-layered clustered?
How to map the keys and values?
How the company manages the data?
How to ignore the incoming data?
How to remove all the events?
How to connect two BLE devices?
How to recover a non-functioning group?
Give a few use cases of Knowledge Objects.
Effect of a non-functioning cluster?
Draw a difference between Splunk app and Splunk add-on?
Does Splunk administration support user authentication systems?
Discuss about the sequence in which splunk upgrade can be done in a clustered environment?
Create new app from templet
Command to change splunkweb port to 9000 via CLI
CLI to validate bundles
Can you name a few most important configuration files in Splunk?
Can you tell some use cases of Knowledge Objects?
Explain about Splunk Enterprise Security (ES)?
Explain about Splunk User Behavior Analytics (UBA)?
Explain Splunk Index Time Process?
Explain Stats vs Transaction commands.
Explain search head pool & search head clusters?
Explain Splunk app? How it differs from Add-on?
Explain the use of License Master in Splunk?
Name the common port numbers used by Splunk.
Name the types of search modes supported in Splunk.
Name the items for migration?
Name the disadvantages of Splunk?
Name the features of a knowledge object?
Name the uses of Knowledge object?
Why is Splunk used for analyzing machine data?
Why do companies adopt Splunk?
Why is Splunk administration used for the analysis of machine data?
Why is Splunk used for the analysis of machine data?
Why people prefer Splunk as compared to other open-source options?
Why use only Splunk?
Why DB connect is important?
Who are the top direct competitors to Splunk?
Who are the competitors of Splunk in the market? Why is Splunk efficient?
Who is responsible for the right quantity of data?
Who analyzes data in a backup system?
Which is the latest Splunk version in use?
Which role can create a data model?
Which Splunk Roles can share the same machine?
Which command is used to the “filtering results” category- explain?
Which role can create data model
Which app ships with splunk enterprise
Where is Splunk Default Configuration stored?
Where does Splunk default configuration file located?
Where to keep the listed data in directories?
When to use auto_high_volume in splunk?
Splunk
  • Cloud topology
  • Splunk Cloud vs Splunk Enterprise
  • Architecture
  • Splunk index - Create, delete, update
  • User Authentication and Authorization
  • Monitor Inputs - Fine-tuning Inputs
  • Manipulating Raw Data
  • Data Parsing and Filtering
  • Deployment Server and Indexer
  • Creating Reports and Visualizations
  • Working with Dashboards
  • Field Aliases and Calculated Fields
  • Field Extractions
  • Creating Tags and Event Types
  • Workflow Actions - GET & Post workflow action
  • Managing Alerts
  • Macros
Components
  • Forwarder Management- UF/HF
  • Common ports
  • Master/Slave relationship
  • Splunk configuration files
  • Basic navigations
Splunk's User Interface
  • Splunk Apps
  • Refine searches
  • Addcoltotals, Addtotals, Append, Appendcols etc.
  • Lookup Table
Search Fundamentals
Fields, Table, Rex, Multikv
  • Reporting Commands- Top, Rare, Stats, Timechart
  • Explore the available visualizations
  • Create a basic chart
  • Split values into multiple series
  • Omit null and other values from charts
  • Create a timechart
  • Chart multiple values on the same timeline
  • Format charts
  • Explain when to use each type of reporting command
Analyzing, Calculating and formatting Results
  • Using the eval command:
  • Perform calculations
  • Convert values
  • Round values
  • Format values
  • Use conditional statements
  • Further filter calculated results

No comments:

Post a Comment

Most views on this month