in

Splunk Interview Questions for Admin

7. What are the unique benefits of getting data into splunk instance via forwarder?

Benefits of getting data into splunk instance via forwarder :

  • Bandwidth throttling
  • TCP connection
  • Encrypted SSL connection

For transferring data from forwarder to an indexer

The data forwarded to the indexer are load balanced  by default even if one indexer is down due to network outage or maintenance purpose the data can be always routed to the another indexer instance in short time.

Also forwarder caches the event locally before forwarding it thus creates backup of data.

8. Which splunk roles can share the same machine?

In small deployment the most of the roles can be shared on same machine as as Search head, Indexer and License master.

In larger deployment to host each host on standalone host

  • Indexers and search head should have physically dedicated machine using Virtual machines for running the instance separately is not the solution  because there are some guidelines for it using computer resources and spinning multiple virtual machines on the same physical hardware can cause performance degradation.
  • you can spin another VM on same instance for hosting the cluster master as long as Deployment server is not hosted parallel on a VM on that same instance because the number of connections coming to deployment server  will be very high.
  • This is because deployment server not only caters to the request coming from deployment master but also request coming from forwarder.

What do you think?

Leave a Reply

Your email address will not be published. Required fields are marked *

GIPHY App Key not set. Please check settings

splunk interview questions for developer

Splunk Interview Questions for Developer

datamodel in splunk

Data Model in Splunk