Professional Documents
Culture Documents
1) What is Splunk?
Ans:
Splunk is Google for your machine data.It's a software/Engine which can be used for
searching,visualizing,Monitoring,reporting etc
of your enterprise data.Splunk takes valuable machine data and turns it into powerful operational intelligence by pro
real
Ans:
Below are common port numbers used by splunk,however you can change them if required
Splunk network port: 514 (Used to get data in from netwok port i.e. UDP data)
KV store 8191
Ans:
POWERED BY Ans:
https://www.learnsplunk.com/splunk-interview-questions.html 1/10
5/10/22, 5:20 PM Splunk interview questions - "This website is not affiliated with Splunk, Inc. and is not an authorized seller of Splunk products or s…
splunk 6.3
Ans:
The indexer is the Splunk Enterprise component that creates and manages indexes. The primary functions of an indexer are:
Ans:
a) universal forwarder(UF) -Splunk agent installed on non-Splunk system to gather data locally, can’t parse or
data
- Generally works as a remote collector, intermediate forwarder, and possible data filter because they parse d
they
Ans:
props.conf
indexes.conf
inputs.conf
transforms.conf
server.conf
Ans:
Enterprise license
Free license
Forwarder license
Beta license
Ans:
Ans:
$splunkhome/etc/system/default
POWERED BY Ans:
https://www.learnsplunk.com/splunk-interview-questions.html 2/10
5/10/22, 5:20 PM Splunk interview questions - "This website is not affiliated with Splunk, Inc. and is not an authorized seller of Splunk products or s…
splunk free lacks these features:
distributed search
deployment management
Ans:
license slave will start a 24-hour timer, after which search will be blocked on the license slave (though indexing cont
users
Will not be able to search data in that slave until it can reach license master again
Ans:
The Summary index is the default summary index (the index thatSplunk Enterprise uses if you do not indicate anoth
one).
If you plan to run a variety of summary index reports you may need to create additional summary indexes.
Ans:
Splunk DB Connect is a generic SQL database plugin for Splunk that allows you to easily integrate database inform
with
15) Can you write down a general regular expression for extracting ip address from logs?
Ans:
There are multiple ways we can extract ip address from logs.Below are few examples.
OR
Ans:
1. Unique id (from one or more fields) alone is not sufficient to discriminate between two transactions. Thi
case
2. when the identifier is reused, for example web sessions identified by cookie/client IP. In this case, time
or pauses
3. are also used to segment the data into transactions. In other cases when an identifier is reused, say in
logs,
4. a particular message may identify the beginning or end of a transaction.
5. When it is desirable to see the raw text of the events combined rather than analysis on the constituent
of the events.
In other cases, it's usually better to use stats as the performance is higher, especially in a distributed search environ
Often there is a unique id and stats can be used.
https://www.learnsplunk.com/splunk-interview-questions.html 3/10
5/10/22, 5:20 PM Splunk interview questions - "This website is not affiliated with Splunk, Inc. and is not an authorized seller of Splunk products or s…
Ans:
Answer to this question would be very wide but basically interviewer would be looking for following keywords in inte
-Check splunkd.log for any errors
-Install SOS (Splunk on splunk) app and check for warning and errors in dashboard
- install Firebug, which is a firefox extension. After it's installed and enabled, log into splunk (using firefox), open fire
panels,
switch to the 'Net' panel (you will have to enable it).The Net panel will show you the HTTP requests and responses
with
the time spent in each. This will give you a lot of information quickly over which requests are hanging splunk for a fe
seconds,
Ans:
Splunk places indexed data in directories, called as "buckets". It is physically a directory containing events of a cer
period.
Hot - Contains newly indexed data. Open for writing. One or more hot buckets for each index.
Warm - Data rolled from hot. There are many warm buckets.
Colld - Data rolled from warm. There are many cold buckets.
Frozen - Data rolled from cold. The indexer deletes frozen data by default, but you can also archive it. Archived data
later be
By default, your buckets are located in $SPLUNK_HOME/var/lib/splunk/defaultdb/db. You should see the hot-db the
and any
warm buckets you have.By default, Splunk sets the bucket size to 10GB for 64bit systems and 750MB on 32bit syst
Ans:
Stats command generate summary statistics of all existing fields in your search results and save them as values in
fields.
Eventstats is similar to the stats command, except that aggregation results are added inline to each event and only
aggregation is pertinent to that event.
eventstats computes the requested statistics like stats, but aggregates them to the original raw data.
Ans:
Ans:
Ans:
POWERED BY
https://www.learnsplunk.com/splunk-interview-questions.html 4/10
5/10/22, 5:20 PM Splunk interview questions - "This website is not affiliated with Splunk, Inc. and is not an authorized seller of Splunk products or s…
Ans:
Ans:
splunk start splunkweb
Ans:
Ans:
Ans:
Ans:
Ans:
Ans:
To reset your password log in to server on which splunk is installed and rename passwd file at below location and th
restart
$splunk-home\etc\passwd
Ans:
Ans:
$splunk_home/var/log/splunk/searches.log
POWERED BY
https://www.learnsplunk.com/splunk-interview-questions.html 5/10
5/10/22, 5:20 PM Splunk interview questions - "This website is not affiliated with Splunk, Inc. and is not an authorized seller of Splunk products or s…
33) What is btool or how will you troubleshoot splunk configuration files?
Ans:
splunk btool is a command line tool that helps us to troubleshoot configuration file issues or just see what values ar
being
34) What is difference between splunk app and splunk add on?
Ans:
Basiclly both contains preconfigured configuration and reports etc but splunk add on do not have visual app. Splunk
have preconfigured visual app
Ans:
Ans:
Its a directory or index at default location /opt/splunk/var/lib/splunk .It contains seek pointers and CRCs for the files
are indexing, so splunkd can tell if it has read them already.We can access it through GUI by seraching for
“index=_thefishbucket”
Ans :
This can be done by defining a regex to match the necessary event(s) and send everything else to nullqueue.Here
basic
example that will drop everything except events that contain the string login In props.conf:
--------------------------------------------------------------------
<code>[source::/var/log/foo]
# index processor
TRANSFORMS-set= setnull,setparsing
</code>
-------------------------------------------------------------------------
In transforms.conf
--------------------------------------------------------------------------------------
POWERED BY
https://www.learnsplunk.com/splunk-interview-questions.html 6/10
5/10/22, 5:20 PM Splunk interview questions - "This website is not affiliated with Splunk, Inc. and is not an authorized seller of Splunk products or s…
[setparsing]
REGEX = login
DEST_KEY = queue
FORMAT = indexQueue
---------------------------------------------------------------------------------------
38. How can i tell when splunk is finished indexing a log file?
Ans:
And if you're having trouble with a data input and you want a way to troubleshoot it, particularly if your whitelist/blac
rules
https://yoursplunkhost:8089/services/admin/inputstatus
Ans:
To do this in Splunk Enterprise 6.0, use ui-prefs.conf. If you set the value in $SPLUNK_HOME/etc/system/local, all
users
1. [search]
2. dispatch.earliest_time = @d
The default time range that all users will see in the search app will be today.
Ans:
$SPLUNK_HOME/var/run/splunk/dispatch contains a directory for each search that is running or has completed. Fo
example,
a directory named 1434308943.358 will contain a CSV file of its search results, a search.log with details about the s
execution, and other stuff. Using the defaults (which you can override in limits.conf), these directories will be deleted
minutes
after the search completes - unless the user saves the search results, in which case the results will be deleted after
days.
41. What is difference between search head pooling and search head clusttering?
POWERED BY
Ans:
https://www.learnsplunk.com/splunk-interview-questions.html 7/10
5/10/22, 5:20 PM Splunk interview questions - "This website is not affiliated with Splunk, Inc. and is not an authorized seller of Splunk products or s…
Both are features provided splunk for high availability of splunk search head in case any one search head goes
down.Search
head cluster is newly introduced and search head pooling will be removed in next upcoming versions.Search
head cluster is
42.If I want add/onboard folder access logs from a windows machine to splunk how can I add same?
Ans:
1.Enable Object Access Audit through group policy on windows machine on which folder is located
2. Enable auditing on specific folder for which you want to monitor logs
Ans:
License violation warning means splunk has indexed more data than our purchased license quota.We have to ide
which
index/sourcetype has received more data recently than usual daily data volume.We can check on splunk license ma
pool
wise available quota and identify the pool for which violation is occurring.Once we know the pool for which we are
receiving more
data then we have to identify top sourcetype for which we are receiving more data than usual data.Once sourcetyp
identified
then we have to find out source machine which is sending huge number of logs and root cause for the same and
troubleshoot
accordingly.
Ans:
Maprduce algorithm is secret behind splunk fast data searching speed.It's an algorithm typically used for batch base
large
Ans:
At indexer splunk keeps track of indexed events in a directory called fish buckets (default location
/opt/splunk/var/lib/splunk).
It contains seek pointers and CRCs for the files you are indexing, so splunkd can tell if it has read them already. - S
more at:
http://www.learnsplunk.com/splunk-indexer-configuration.html#sthash.t1ixi19P.dpuf.
Ans:
Splunk SDKs are designed to allow you to develop applications from the ground up and not require Splunk Web or
components from the Splunk App Framework. These are separately licensed to you from the Splunk Software and d
alter
the Splunk Software.Splunk App Framework resides within Splunk’s web server and permits you to customize the S
Web
UI that comes with the product and develop Splunk apps using the Splunk web server. It is an important part of the
POWERED BY features
https://www.learnsplunk.com/splunk-interview-questions.html 8/10
5/10/22, 5:20 PM Splunk interview questions - "This website is not affiliated with Splunk, Inc. and is not an authorized seller of Splunk products or s…
and functionalities of Splunk Software , which does not license users to modify anything in the Splunk Software.
47. For what purpose inputlookup and outputlook are used in splunk search?
Ans:
For example
…| inputlookup lookuptabllename returns a search result for every row in the table lookup which has tw
field
alues:
v
• host
• machine_type.
Outputlookup outputs the current search results to a lookup table on the disk.
For example
For more realtime scenario based interview questions please contact admin@learnsplunk.com
Your suggestions are valuable for us.Please comments in case you have any questions or suggestions.
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
-------------------------
Comments
Name
POWERED BY
https://www.learnsplunk.com/splunk-interview-questions.html 9/10
5/10/22, 5:20 PM Splunk interview questions - "This website is not affiliated with Splunk, Inc. and is not an authorized seller of Splunk products or s…
Kaleb · Mar 4, 2017
The Q&A session is very helpful to understand the full scope of Splunk architecture and Splunk features.
Like · Reply · Flag
Showing 1 to 10
POWERED BY
https://www.learnsplunk.com/splunk-interview-questions.html 10/10