Splunk Enterprise

Splunk Interview Question?

karthi2809
Builder

Hi All,

I am new to splunk clustering environment and i have few questions when i attend interview.Any one please help me on this question

1.Can we delete index folder ?will we have permission to delete the index folder Splunk\var\lib\splunk\TestDB.

2.Can we copy the Index folder and paste it in someother index folder will be able to search the logs?

3.Where can we install DB connect app and other apps in Search head cluster OR Indexer Server cluster?

4.What is the process name when we extract logs from props and transform.conf file?

5.Upgrade Splunk cluster enironment with simple steps?

6.What is the process of search head captain will do ?

Thanks,

Karthigeyan R

Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

To most of those questions answers can be found on Splunk documentation pages. Some of them require a bit of experience with the system. Both knowing the docs as well as experience sums up to product knowledge and abilities which are required to work with the product. Unless it's a very entry-level position where you should learn everything from scratch (but for such work you shouldn't get such questions in interview), you should know this before trying to administer Splunk environments. Otherwise you can do some very costly damage to your (potential) employer installation.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
if you are looking any workplace, where you are needing knowledge about those answers? I strongly propose, that you start your learning path to Splunk Certified System Admin to understand enough, what splunk is and how it will work.
r. Ismo
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...