Explain the splunk architecture?
What are the components of splunk/splunk architecture?
What are splunk buckets? Explain the bucket lifecycle?
How are forwarder licenses purchased?
Explain the difference between search head pooling and search head clustering?
What is the output lookup command?
When to use auto_high_volume in splunk?
Define calculated fields?
Explain the use of top command in splunk?
What is the use of spath command?
Name companies which are using splunk?
What is join command and what are various flavours of join command?
What is difference between stats and timechart command?
Define reports in splunk?
How many roles are there in splunk?