Here we will be adding all the possible list of splunk interview questions for developer & answers that can be asked by a interviewer in interview.
List of splunk interview questions for developer:
1. Best practice while writing a query?
index=<indexname> Source=<"abc.csv"> host=<hostname> sourcetype=<sourcetype>
- Filter your data.
- Eval the search
2. Difference between report and alert?
The main difference between an alert and a report is the trigger condition. With the trigger condition an alert will only do an action under the specified circumstances. Where a scheduled report will always do it’s action if one is selected and an unscheduled report will only run when chosen.
GIPHY App Key not set. Please check settings