Splunk Interview Questions and Answer Part – 1

Where is the best place to get help with general Splunk questions?

  • Splunk Answers (Ans)
  • Stack Overflow
  • Course Q and A

Splunk is primarily a business intelligence tool.

  • False (Ans)
  • True

To be successful in this course, you should commit to _ per day.

  • 10 – 20 minutes (Ans)
  • 1 to 2 hours
  • 30 – 45 minutes
  • 0 minutes

Splunk can be used to

  • investigate.
  • alert.
  • build dashboards.
  • build reports.
  • all of these (Ans)

Splunk is free for up to 5GB of incoming data per day.

  • True
  • False (Ans)

This course is “version agnostic.”

  • False
  • True (Ans)

You need a lot of prior experience in IT or Business Intelligence to be successful in this course.

  • True
  • False (Ans)

Where is Splunk headquartered?

  • New York
  • Boston
  • UK
  • San Francisco (Ans)
  • Palo Alto

You need to understand a complicated search language to use Splunk successfully.

  • False (Ans)
  • True

Splunk can make you the “hero” of your IT department.

  • True (Ans)
  • False

The Splunk Enterprise Trial license is valid for

  • 30 days.
  • 90 days.
  • 60 days (Ans)
  • 45 days.

To collect and parse data at the source, you need a

  • light forwarder.
  • universal forwarder.
  • heavy forwarder. (Ans)
  • indexer.
  • parser.

Splunk can be set up in a distributed environment.

  • False
  • True (Ans)

Splunk can be installed in the following environments:

  • Unix
  • Linux.
  • Windows.
  • Mac.
  • All of these. (Ans)
  • Solaris.

Select the best description of a Splunk app.

  • A particular configuration setting found in a config file. (Ans)
  • A collection of configuration files that extend the functionality of Splunk.
  • A competitor to Splunk, like Elk.
  • A heavy forwarder that is installed with a forwarder license.

A licensing violation is in effect for

  • 90 days.
  • 30 days. (Ans)
  • 60 days.
  • 45 days.

Splunk will stop indexing your data during the violation period.

  • False (Ans)
  • True

To manage licensing in the Splunk GUI, navigate to

  • Settings / Server controls.
  • Settings / Forwarder management.
  • Settings / Licensing. (Ans)
  • Settings / Access controls.

Search is a Splunk app.

  • False
  • True (Ans)

Where should you go to find and download Splunk apps?

  • applications.splunk.com
  • splunkers.com
  • splunkbase.com (Ans)
  • install.splunk.com