in

Splunk Interview Questions for Developer

3. Difference between apps vs addons?

Both are packaged and uploaded to Splunk Apps as SPL files and then to install them in your Splunk instance you simply untar the SPL file into etc/apps .But the content and purpose of Apps and Add-ons certainly differ from one another.

  • Apps package together Splunk features like saved searches, dashboards and inputs into their own GUI.
  • Splunk Apps are considered to be the entire collection of reports, dashboards, alerts, field extractions and lookups.
  • Add-ons are smaller components that don’t have their own GUI and may need some extra configuration.
  • Splunk Apps minus the visual components of a report or a dashboard are Splunk Add-ons. Lookups, field extractions, etc are examples of Splunk Add-on.

4. Different methods to install apps?

  1. Log in the splunkweb and Navigate to apps>manage apps
  2. click install app from file
  3. Upload an file click under file and go search the app that you want to install.
  4. Click on upload after your restart splunk web

5. Can app be restricted upon user?

Yes, It can be restricted upon user.

  • first, you create a role, and eventually put users with that role.
  • go to you app settings (manager > apps > permissions) and put the permissions to only the members of this group (and admin at least) this will also be the default permissions to any object of this app (but you can probably change individually later.

What do you think?

Leave a Reply

Your email address will not be published. Required fields are marked *

GIPHY App Key not set. Please check settings

splunk interview questions

Common Splunk Interview Questions

splunk interview questions for admin

Splunk Interview Questions for Admin