What is the main difference between source & source type?
Answer / Brijesh Kumar Singh
Source refers to the location where data is ingested by Splunk, such as a log file or database. Source Type is a categorization of the source that helps Splunk parse and index the data more efficiently, based on the structure of the data.
| Is This Answer Correct ? | 0 Yes | 0 No |
Explain search factor (sf)?
What are types of splunk licenses?
Which command is used to the “filtering results” category- explain?
How is it possible to use the host value and not ip address or the dns name for a tcp input?
What are the pros of getting data into a splunk instance using forwarders?
What is the main difference between sort + and sort -?
Explain splunk rest api?
How to exclude some events from being indexed by splunk?
Define reports in splunk?
Explain pivot and data models?
What is a lookup command? Differentiate between inputlookup & outputlookup commands.
What are the formats in which search result be exported?