Explain about Splunk architecture and various stages?
What is splunk app? What is the difference between splunk app and add-on?
How to disable splunk launch message?
What is the use of time zone property in splunk? When is it required the most?
How to troubleshoot splunk performance issues?
What would you use to view contents of a large file? How to copy/remove file? How to look for help on a Linux?
Explain workflow actions?
What happens if the license master is unreachable?
What is the difference between the splunk app framework and splunk sdks?
Define monitoring in splunk?
List out some splunk search commands?
Which role can create data model?
What is the eval command?
What are the different options while setting up alerts?
What is join command and what are various flavours of join command?