What is a lookup command? Differentiate between inputlookup & outputlookup commands.
What is the command to get list of configuration files in Splunk?
Why use only splunk?
What is stool or how will you troubleshoot splunk configuration files?
Explain search factor (sf) & replication factor (rf)?
Why should we use splunk alert?
How to reset the splunk administrator password?
What is the main difference between source & source type?
How to Create new app from templet?
Explain the use of top command in splunk?
What is the difference between ‘eval’, ‘stats’, ‘charts’ and ‘timecharts’ command?
What is join command and what are various flavours of join command?
How splunk avoids duplicate indexing of logs?
Explain how data ages in splunk?
What are three versions if splunk?