The short answer: Splunk interviews cover architecture (forwarders, indexers, search heads, and how data moves through them), the Search Processing Language (SPL), knowledge objects (field extractions, lookups, alerts, dashboards), search performance, and troubleshooting. Administrator roles go deeper into deployment, clustering and data onboarding; SOC analyst roles focus on writing searches to investigate security events; developer roles on apps, dashboards and APIs. Expect to write SPL live.
Architecture questions
“What are the main Splunk components?”
Splunk’s documentation lists three fundamental components of a distributed deployment:
- Forwarders collect data and send it to indexers. A universal forwarder is lightweight and does minimal processing; a heavy forwarder can parse and filter data before sending it.
- Indexers parse, index and store data, and run searches on their local data.
- Search heads handle users’ searches, distribute them to indexers, and merge the results.
Management components include the deployment server (pushes configurations and apps to forwarders), the indexer cluster manager node, and the search head cluster deployer.
“How does data move through Splunk?”
Through the data pipeline: input (forwarders or indexers receive data), parsing (breaking data into events, extracting timestamps, applying index-time transformations, on indexers or heavy forwarders), indexing (writing to indexes on disk), and search (search heads and indexers).
“What are indexes and buckets?”
An index is where events are stored, usually separated by data type, retention or access needs (for example, firewall logs in one index and application logs in another). Data in an index ages through buckets: hot (being written), warm, cold, and frozen (deleted or archived) based on size and retention settings.
“What’s the difference between index-time and search-time field extraction?”
Index-time extraction happens during parsing and is stored with the data; it’s rarely needed and increases index size. Search-time extraction (the default and usually preferred) happens when you search, using props and transforms, so you can change it without reindexing.
SPL questions
- “What does
statsdo?” Calculates aggregates (count, sum, average, distinct count) grouped by fields:index=web status=500 | stats count by host. - “What’s the difference between
stats,eventstatsandstreamstats?”statsreturns only the aggregates;eventstatsadds aggregates to each event;streamstatscalculates running statistics in event order. - “How do you chart over time?”
timechart:index=web | timechart span=1h count by status. - “How do you extract a field with a regular expression?”
rex:| rex field=_raw "user=(?<user>\w+)". - “How do you enrich events?” With lookups:
| lookup assets.csv ip AS src_ip OUTPUT owner, criticality. - “What does
evaldo?” Creates or changes fields with expressions:| eval duration_min = duration / 60.
“When would you use transaction instead of stats?”
Splunk’s documentation says transaction is most useful when a unique ID alone isn’t enough to tell transactions apart (for example, web sessions identified by a reused cookie or IP, split by time gaps), or when you want to see the raw events combined. Otherwise, it’s usually better to use stats, which performs more efficiently, especially in a distributed environment:
index=app | stats min(_time) AS start, max(_time) AS end, count BY session_id
| eval duration = end - start
Knowledge objects
Saved searches, reports, alerts, dashboards, field extractions, lookups, event types, tags, macros, and data models. Know how permissions and sharing work (private, app, global) and how to schedule an alert with throttling to avoid duplicate notifications.
Performance questions
“How do you make a slow search faster?”
- Narrow early: specify the index, sourcetype and a tight time range at the start of the search.
- Filter before transforming: put search terms before
statsand other commands. - Prefer
statstotransactionandjoinwhere possible. - Use accelerated data models and
tstatsfor large, repeated searches. - Avoid leading wildcards and unnecessary
fieldsextraction of everything.
Troubleshooting questions
“Data from a server isn’t showing up. What do you check?”
- Forwarder: is it running and connected to the indexers? Check its logs (
splunkd.log) andoutputs.conf. - Inputs: is the right file or port configured in
inputs.conf, with read permissions? - Index and sourcetype: is data going to an index you have permission to search, with the expected sourcetype?
- Time: are timestamps parsed correctly? Events with wrong time zones may sit outside your search window.
- Internal logs: search
index=_internalfor errors from that host.
SOC analyst questions
- “How would you search for brute-force login attempts?” Count failed logins by user and source over a short window and alert above a threshold:
index=auth action=failure | bin _time span=5m | stats count by user, src_ip, _time | where count > 20. - “How do you investigate an alert?” Confirm it’s real, scope it (which hosts and users, since when), pivot across data sources, contain, document, and tune the rule if it was a false positive.
Related guides: security engineer interview questions, DevOps engineer interview questions and site reliability engineer interview questions.
Frequently asked questions
What are the main components of Splunk?
What is the difference between a universal and a heavy forwarder?
When should you use transaction instead of stats in Splunk?
How do you speed up a Splunk search?
What SPL commands should I know for an interview?
Sources
- Splunk Documentation, Components and the data pipeline. Read on 1 October 2026.
- Splunk Documentation, About transactions. Read on 1 October 2026.