Documente Academic
Documente Profesional
Documente Cultură
8. what are most important configuration files of splunk OR can you tell name of
few important configuration files in splunk?
props.conf
indexes.conf
inputs.conf
transforms.conf
server.conf
Free license
Forwarder license
Beta license
If you plan to run a variety of summary index reports you may need to create
additional summary indexes.
Learn more about Splunk in this Splunk training in New York to get ahead in your
career!
15. What is splunk DB connect?
Splunk DB Connect is a generic SQL database plugin for Splunk that allows you to
easily integrate database information with Splunk queries and reports.
16. Can you write down a general regular expression for extracting ip address from
logs?
There are multiple ways we can extract IP address from logs. Below are few
examples.
Unique id (from one or more fields) alone is not sufficient to discriminate between
two transactions. This is the case
when the identifier is reused, for example web sessions identified by cookie/client
IP. In this case, time span or pauses are also used to segment the data into
transactions.
In other cases when an identifier is reused, say in DHCP logs, a particular message
may identify the beginning or end of a transaction.
When it is desirable to see the raw text of the events combined rather than
analysis on the constituent fields of the events.
In other cases, it�s usually better to use stats as the performance is higher,
especially in a distributed search environment.
Often there is a unique id and stats can be used.
18. How to troubleshoot splunk performance issues?
Answer to this question would be very wide but basically interviewer would be
looking for following keywords in interview :
Hot � Contains newly indexed data. Open for writing. One or more hot buckets for
each index.
Warm � Data rolled from hot. There are many warm buckets.
Cold � Data rolled from warm. There are many cold buckets.
Frozen � Data rolled from cold. The indexer deletes frozen data by default, but you
can also archive it. Archived data can later be thawed (Data in frozenbuckets is
not searchable)
By default, your buckets are located in:
$SPLUNK_HOME/var/lib/splunk/defaultdb/db
You should see the hot-db there, and any warm buckets you have. By default, Splunk
sets the bucket size to 10GB for 64bit systems and 750MB on 32bit systems.
Interested in learning Splunk? Click here to learn more in this Splunk Training!
Eventstats is similar to the stats command, except that aggregation results are
added inline to each event and only if the
eventstats computes the requested statistics like stats, but aggregates them to the
original raw data.
Interested in learning Splunk? Click here to learn more in this Splunk Training in
Tornoto!
[user_info]
PASSWORD = NEW_PASSWORD
In the place of �NEW_PASSWORD�, just add your own new password
After that just start the Splunk Enterprise and use the new password to log in
In case you have created other users earlier and know their login details, copy and
paste their credentials from the passwd.bk file into the passwd file and restart
Splunk.
Now, if you are using the versions prior to 7.1, follow the below steps:
$splunk_home/var/log/splunk/searches.log
34. What is btool or how will you troubleshoot splunk configuration files?
splunk btool is a command line tool that helps us to troubleshoot configuration
file issues or just see what values are being used by your Splunk Enterprise
installation in existing environment
35. What is difference between splunk app and splunk add on?
Basiclly both contains preconfigured configuration and reports etc but splunk add
on do not have visual app. Splunk apps have preconfigured visual app
index=_thefishbucket
Are you interested in learning Splunk course in Bangalore from Experts?
<code>[source::/var/log/foo]
# index processor
TRANSFORMS-set= setnull,setparsing
</code>
In transforms.conf:
[setparsing]
REGEX = login
DEST_KEY = queue
FORMAT = indexQueue
39. How can i tell when splunk is finished indexing a log file?
By watching data from splunk�s metrics log in real time.