How can you exclude some events from being indexed in Splunk?
What would you use to view contents of a large file? How to copy/remove file? How to look for help on a Linux?
How to show which deployment server in configured to pull data from?
Where does splunk default configuration is stored?
How would you handle/troubleshoot splunk license violation warning error?
What is the use of stats command?
Explain search factor and replication factor?
What are most important configuration files of splunk or can you tell name of few important configuration files in splunk?
Differentiate between inputlookup & outputlookup commands.
Explain pivot and data models?
How does splunk determine 1 day, from a licensing perspective?
What are the lookup command and its use case?
Which commands are included in ‘filtering results’ category?
Why is splunk used for analyzing machine data?
Name stages of splunk indexer?