Explain how splunk works?
What is the difference between splunk app and add-on?
Explain splunk rest api?
What is difference between source & source type?
What do you mean by roles based access control?
What is the command to stop and start Splunk service?
Differentiate between inputlookup & outputlookup commands.
Give me the syntax of Case command?
Can you write down a general regular expression for extracting ip address from logs?
Explain types of search modes in splunk?
How are forwarder licenses purchased?
Why should we use splunk alert? What are the different options while setting up alerts?
What is difference between stats and timechart command?
Define search head pooling?
Name the command which is used to the “filtering results” category?