Find the Best Cosmetic Hospitals

Explore trusted cosmetic hospitals and make a confident choice for your transformation.

“Invest in yourself — your confidence is always worth it.”

Explore Cosmetic Hospitals

Start your journey today — compare options in one place.

Splunk Interview Questions and Answer Part – 4

Which file is used for role and mapping

  • authorize.conf (Ans)
  • authorizes.conf
  • authentication.conf
  • limits.conf

You can not search the data in frozen stage of bucket

  • True (Ans)
  • False

Attributes in indexes.conf to freeze data when it grows too old

  • frozenTimePeriodInSecs (Ans)
  • frozenTimePeriodInMinutes
  • frozenTimePeriodInHour
  • MaxDataSizeInMb

Which Splunk License does not exist

  • search head (Ans)
  • forwarder
  • free
  • Splunk Enterprise

You can not back up hot buckets

  • Yes, you can not do
  • No , you can back up hot buckets
  • You can back up hot buckets as well, you need to take a snapshot of the files, using a tool like VSS.
  • Its not possible to take backup of hot buckets (Ans)

Why you should create multiple indexes?

  • To control user access.
  • To accommodate varying retention policies.
  • To speed searches in certain situations.
  • All of the above. (Ans)

Which command is used only to delete index web data ?

  • splunk clean eventdata -index web (Ans)
  • splunk clean eventdata
  • splunk remove -index web
  • splunk disable -index web

What is the use of Add-on in splunk?

  • To create dashboards
  • To run only scripts
  • To extract fields, parsing etc but do not provide dashboards (Ans)
  • To replace App

In which index, events from the file system change monitor, auditing, and all user search history are stored.

  • audit
  • _audit (Ans)
  • index
  • _index
  • main

Can you create new index starting with _ in splunk web-gui ?

  • Yes
  • No (Ans)
  • You can create but it is not recommended by Splunk

Deployment server push configuration files to deployment client

  • True
  • False (Ans)

Deployment client uses which configuration files to connect deployment server ?

  • serverclass.conf
  • deploymentclient.conf (Ans)
  • inputs.conf
  • outputs.conf

universal forwarder can index the data

  • True
  • False (Ans)

Which component should not have web gui?

  • Search Head
  • Deployment Server
  • Universal Forwarder (Ans)
  • Heavy Forwarder

Search Head can not index the data.

  • True
  • False (Ans)

Which index includes Splunk Enterprise internal logs and metrics.

  • _internal (Ans)
  • audit
  • main
  • _audit

The deployment server does not automatically deploy apps when you edit through forwarder management.

  • True
  • False (Ans)

The deployment server does not automatically deploy apps in response to direct edits of serverclass.conf

  • True (Ans)
  • Flase

A dedicated deployment server can handle how many clients ?

  • 50
  • 100
  • 400
  • 500 – 1000 clients, even more than this and it depends of the periodicity, and the size of the bundles to deploy. (Ans)

Which is used in script stanza ?

  • monitor
  • script (Ans)
  • fschange

which attribute can be used to run a script in every 5 minutes

  • interval = 5
  • interval = 300 (Ans)
  • interval = 1800
  • cron = 300

which can be used in stanza to destroy file after reading the file

  • fschange
  • monitor
  • batch (Ans)
  • destroy

To receive data from forwarder in indexer in inputs.conf file, which is used in stanza ?

  • tcp
  • splunktcp (Ans)
  • udp
  • forwardertcp

Find Trusted Cardiac Hospitals

Compare heart hospitals by city and services — all in one place.

Explore Hospitals
I’m a DevOps/SRE/DevSecOps/Cloud Expert passionate about sharing knowledge and experiences. I have worked at <a href="https://www.cotocus.com/">Cotocus</a>. I share tech blog at <a href="https://www.devopsschool.com/">DevOps School</a>, travel stories at <a href="https://www.holidaylandmark.com/">Holiday Landmark</a>, stock market tips at <a href="https://www.stocksmantra.in/">Stocks Mantra</a>, health and fitness guidance at <a href="https://www.mymedicplus.com/">My Medic Plus</a>, product reviews at <a href="https://www.truereviewnow.com/">TrueReviewNow</a> , and SEO strategies at <a href="https://www.wizbrand.com/">Wizbrand.</a> Do you want to learn <a href="https://www.quantumuting.com/">Quantum Computing</a>? <strong>Please find my social handles as below;</strong> <a href="https://www.rajeshkumar.xyz/">Rajesh Kumar Personal Website</a> <a href="https://www.youtube.com/TheDevOpsSchool">Rajesh Kumar at YOUTUBE</a> <a href="https://www.instagram.com/rajeshkumarin">Rajesh Kumar at INSTAGRAM</a> <a href="https://x.com/RajeshKumarIn">Rajesh Kumar at X</a> <a href="https://www.facebook.com/RajeshKumarLog">Rajesh Kumar at FACEBOOK</a> <a href="https://www.linkedin.com/in/rajeshkumarin/">Rajesh Kumar at LINKEDIN</a> <a href="https://www.wizbrand.com/rajeshkumar">Rajesh Kumar at WIZBRAND</a> <a href="https://www.rajeshkumar.xyz/dailylogs">Rajesh Kumar DailyLogs</a>

Related Posts

What is Splunk and use cases of Splunk?

What is Splunk? Splunk is a powerful data analytics and visualization platform designed for log management, monitoring, and real-time data analysis. It is widely used across industries…

Read More

Top 10 SecOps Tools: Enhance Your Security Operations with These Cutting-Edge Solutions

Hey there, my fellow security enthusiasts! Are you tired of dealing with security breaches and attacks on a daily basis? Do you want to take your security…

Read More

What is Splunk and How it works? An Overview and Its Use Cases

History & Origin of Splunk Rob Das and Eric Swan co-founded this technology in the year 2003 as a solution to all the questions raised while investigating…

Read More

What is Splunk SIEM and How it works? An Overview and Its Use Cases

History & Origin of Splunk SIEM The Splunk platform removes the barriers between data and action, empowering observability, IT and security teams to ensure their organizations are…

Read More

Top 50 Interview questions and Answers for Splunk SIEM

The Splunk is a technology that is used for searching, monitoring, picturing, and analyzing machine data on an actual source. It is a tool for log supervision…

Read More

Top 50 Splunk interview questions and answers

1) Define Splunk It is a software technology that is used for searching, visualizing, and monitoring machine-generated big data. It monitors and different types of log files…

Read More