Splunk · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
26% of exam · 6 sample questions below
A Splunk admin wants to enrich web server logs with geographic location data based on IP addresses. Which approach should they use?
Configure a lookup definition and use lookup command
A lookup definition maps IP address fields to a CSV or KV Store containing geographic data, and the lookup command enriches each event at search time. This satisfies the stem's enrichment requirement without altering indexed data or requiring a separate geoip transform.
Use rex to extract location from the IP
Use an eval command to calculate coordinates
Use fields command to add location
A search includes a lookup that returns multiple values per event. The admin wants to see each matched value as a separate event. Which command should be used after the lookup?
mvexpand
mvexpand splits a multivalue field into separate events, one per value, so each lookup-matched value appears as its own result row. This directly satisfies the requirement to view every matched value individually rather than as a combined multivalue field.
untable
stats
makemv
In Splunk, which of the following is true about fields?
Fields are extracted at search time from raw data
Splunk extracts fields at search time from raw indexed events, using default knowledge objects or inline commands, rather than storing them at index time. This lets users define new fields without reindexing, which is the defining behaviour of search-time field extraction.
Fields must be manually defined before indexing
Fields are only available after using the fields command
All fields are predefined by Splunk
A search uses a lookup that returns a field 'priority'. The admin wants to use the lookup only for events where the 'source' is 'firewall'. Which command should be used?
source=firewall | lookup priority_lookup source OUTPUT priority
Filtering with source=firewall before the lookup restricts enrichment to firewall events only. The lookup then matches on the source field and returns priority via OUTPUT, so other event sources remain unaffected, meeting the constraint that the lookup applies solely to firewall-sourced events.
| lookup priority_lookup source OUTPUT priority
| lookup priority_lookup source OUTPUT priority | where source="firewall"
| lookup priority_lookup source OUTPUT priority WHERE source="firewall"
Which of the following best describes the purpose of the 'fields' command in a search?
To keep or remove specified fields from events
The fields command includes or excludes fields from results, either keeping (+) named fields or removing (-) them. This matches the stated purpose of retaining or dropping specified fields, distinguishing it from table, which also reformats and reorders output.
To rename existing fields
To add fields from a lookup table
To extract new fields from raw data
A user wants to create a field that contains the length of the 'message' field. Which command should they use?
rex field=message "(?<msg_length>.*)"
eval msg_length=sizeof(message)
len(message)
eval msg_length=len(message)
The `eval` command creates a new field, and its `len()` function returns the character count of a string, so `msg_length=len(message)` satisfies the requirement to derive the length of the 'message' field. `eval` is the correct command for computing calculated fields in Splunk search processing language.
Want more Using Fields and Lookups practice?
Practice this domain5% of exam · 6 sample questions below
A new Splunk user wants to view the raw event data for the last hour. Which interface should they use?
Search History
Settings
Data Summary
Search & Reporting
Search & Reporting provides the search bar, time-range picker and raw event display needed to inspect events from the last hour. It is the primary interface for ad-hoc searching, directly satisfying the requirement to view raw event data.
An analyst notices that searches take long to complete. They want to understand how many events are indexed per second. Which tab in the Monitoring Console provides this information?
Indexing Performance
Indexing Performance displays indexing throughput metrics, including events indexed per second, directly satisfying the analyst's need to quantify indexing rate. Its panels aggregate indexer-level counters such as event ingestion rate and queue activity, so the analyst can pinpoint whether slow searches stem from indexing bottlenecks rather than search-time processing.
License Usage
Search Performance
Forwarder Management
A search returns no results. The user has verified that data is being indexed. What is the most likely cause?
The search term is misspelled
The search is using incorrect index name
The time range picker is set incorrectly
Splunk searches default to a limited time range, so correctly indexed events outside that window return nothing. Adjusting the time range picker to cover the indexed data's actual timestamps restores results, satisfying the no-results scenario.
The user lacks search permissions
A user wants to see a visual representation of search results over time. Which tab should they use?
Visualizations
The Visualizations tab renders search results graphically, including time-series charts that plot events across the search time range. This directly satisfies the user's requirement for a visual representation over time, whereas the Statistics tab only returns tabular aggregates and the Patterns tab surfaces recurring event structures.
Patterns
Events
Statistics
Which TWO of the following are valid ways to share a Splunk dashboard?
Send via email
Share via URL
Dashboards can be shared by distributing a direct link, letting recipients open the dashboard in their browser provided they hold the necessary permissions. This satisfies the sharing requirement without exporting or embedding, since access is governed by the recipient's Splunk role.
Export as PDF
Embed as iframe
Embedding as an iframe publishes the dashboard's REST endpoint inside another web page, letting external portals display live panels. Splunk supports this through the dashboard's embed token, making it a valid sharing method distinct from URL sharing.
Clone dashboard
Which THREE of the following are default Splunk roles?
admin
Splunk ships with admin as a built-in default role, granting full access to all features, settings and knowledge objects across the deployment. It is one of the predefined roles available immediately after installation, satisfying the question's requirement for default roles.
power
Power is one of Splunk's default roles, shipping with every installation alongside user, admin, can_delete, and others. It satisfies the stem's requirement for built-in roles by granting broad search capabilities without administrative privileges, unlike custom roles created later. No configuration is needed to make it available.
manager
operator
user
The user role ships with Splunk by default, granting search capabilities over assigned indexes without administrative privileges. It is one of the built-in roles created during installation, alongside admin, power, can_delete and others, so it satisfies the question's requirement for a default Splunk role.
Want more Splunk Basics and Interface Navigation practice?
Practice this domain52% of exam · 6 sample questions below
A security analyst needs to identify the top 5 source IP addresses generating the most web traffic. Which command should be used?
| stats count by src_ip | sort - count
| top limit=5 src_ip
The top command with limit=5 returns the five most frequent values of src_ip, ranked by count, which directly answers the requirement to identify the top 5 source IP addresses. Splunk's top operator performs this aggregation natively.
| sort - count | head 5
| table src_ip | head 5
A search returns events with a field 'duration' in milliseconds. The analyst wants to create a new field 'duration_sec' that divides duration by 1000. Which command accomplishes this?
| rename duration as duration_sec
| convert duration_sec = duration/1000
| eval duration_sec = duration / 1000
The `eval` command creates a new field by evaluating an expression, satisfying the requirement to derive `duration_sec` from `duration`. Dividing by 1000 converts milliseconds to seconds, and the result is assigned to the new field name. Unlike `where` or `search`, `eval` computes and stores values rather than filtering events.
| fields duration_sec = duration/1000
A search returns 1,000 events. The analyst wants to see the first 10 events sorted by the '_time' field in descending order. Which search is correct?
| sort by _time | head 10
| sort -_time | head 10
Sorting by `-_time` orders events newest first, satisfying the descending requirement, and `head 10` then returns only the first ten rows. Because `sort` precedes `head`, the pipeline truncates after ordering, so the analyst sees the ten most recent events rather than an arbitrary subset.
| sort +_time | head 10
| sort _time | head 10
A search includes the command '| stats dc(user) by host'. What does this command return?
The number of unique hosts per user
The count of events per host
The sum of user values per host
The number of distinct users per host
The dc() function counts distinct values, so dc(user) returns the unique user count. Grouping by host with by host splits results per host, yielding the number of distinct users for each host rather than a single total.
Which TWO commands can be used to filter events based on a field value? (Choose two.)
eval
search
The search command filters events by matching keywords and field-value pairs in the raw event data, returning only events that satisfy the criteria. It is a core filtering command, unlike transforming commands such as stats or table.
stats
where
The `where` command filters events using eval-based expressions, evaluating field values with operators such as equals, greater than, or boolean logic. This satisfies the stem's requirement to filter events based on a field value, unlike transforming commands that merely aggregate or reorder results without conditional evaluation.
table
Which THREE of the following are valid uses of the 'eval' command? (Choose three.)
Grouping events by a field: eval by host
Concatenating two strings: eval fullname = firstname + " " + lastname
The eval command supports string concatenation using the plus operator, so joining firstname, a space and lastname into a new fullname field is valid. This directly satisfies the question's requirement for a legitimate eval use case.
Sorting events by a field: eval sort by _time
Calculating a ratio: eval ratio = count / total
The `eval` command creates a new field by evaluating an expression, so `eval ratio = count / total` performs arithmetic division across two existing fields and writes the result into `ratio`. This satisfies the stem's requirement for a valid `eval` use, since calculated-field arithmetic is a core function.
Creating a conditional field: eval status = if(error > 0, "Error", "OK")
The eval command's if() function evaluates a boolean condition and returns one of two specified values, so assigning "Error" or "OK" based on error > 0 is valid. This meets the question's requirement for a legitimate eval use.
Want more Basic Searching and Transforming Commands practice?
Practice this domain17% of exam · 6 sample questions below
A security team needs to create a report that shows the number of distinct users who triggered a firewall block each day for the past 30 days. Which search and visualization combination should be used?
Use `dc(user)` with `chart` and a column chart
Use `top user` with `timechart` and a pie chart
Use `dc(user)` with `timechart` and a column chart
Using `dc(user)` supplies the distinct count the report requires, while `timechart` buckets results into daily intervals across the 30-day span. A column chart then renders each day's distinct-user total as a discrete bar, satisfying both the daily grouping and distinct-count constraints in the stem.
Use `count` with `chart` and a bar chart
A user wants to create a dashboard panel that refreshes automatically every 60 seconds. Which setting must be configured in the panel's edit mode?
Add | delay 60 to the search
Set the Refresh Interval to 60 seconds
Splunk dashboards refresh panels via the panel's Refresh Interval setting, which accepts a time value in seconds. Configuring 60 seconds causes the search to re-run automatically, directly meeting the stem's requirement for a panel refreshing every minute.
Schedule the search to run every 60 seconds
Set the Time Range to Last 60 seconds
A dashboard includes a table showing server errors. The team wants to click a row and drill down to a detailed view of that server's events in a new search. Which configuration is required?
Enable row expansion in the table options
Add a link to the search in the table using 'Link to external resource'
Set the drilldown action to 'Search' in the table's edit panel
Configuring the table's drilldown to 'Search' makes clicking a row launch a new search using tokens from that row, such as the server field. This satisfies the requirement to open a detailed event view for the selected server.
Use the `drilldown` search command in the underlying search
Which TWO statements are true about saved reports in Splunk?
All saved reports automatically send email alerts.
Saved reports are created exclusively from dashboard panels.
Saved reports can be used as data sources for dashboard panels.
Saved reports function as reusable knowledge objects, so a dashboard panel can reference one directly as its data source rather than embedding raw search strings. This satisfies the stem's requirement for a true statement, since panels inherit the report's saved search, time range and permissions without duplication.
Saved reports can be scheduled to run at specific times.
Scheduling saved reports satisfies the requirement to run searches automatically at defined intervals. Splunk's report scheduling uses cron expressions to trigger saved searches, enabling recurring execution without manual intervention. This directly addresses the constraint of running reports at specific times, confirming the statement's accuracy.
Saved reports cannot be edited after creation.
Which TWO chart types are best suited for showing the distribution of categorical data?
Scatter chart
Line chart
Area chart
Pie chart
A pie chart partitions a whole into proportional slices, directly depicting how categorical values distribute across a total. It satisfies the distribution requirement by showing each category's relative share rather than a trend over time.
Column chart
A column chart plots each category as a discrete bar whose height encodes frequency, making the distribution across categorical values directly comparable. It satisfies the distribution requirement without implying any continuous or temporal relationship between categories.
A user wants to create a report that shows the average response time for each web endpoint over the past week. The data has fields: endpoint, response_time. Which search correctly calculates the average?
... | stats avg(response_time) by endpoint
The `stats` command with `avg()` calculates the mean response_time, while the `by endpoint` clause splits results into one row per endpoint — exactly the per-endpoint grouping the report requires. The week-long window is handled by the search's time range picker, not the command itself.
... | stats mean(response_time) by endpoint
... | stats avg(response_time) by _time
... | eval avg=sum(response_time)/count | stats values(avg) by endpoint
Want more Creating Reports, Dashboards and Visualizations practice?
Practice this domainThe SPLK-1001 exam has 65 questions and must be completed in 60 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 4 domains: Using Fields and Lookups, Splunk Basics and Interface Navigation, Basic Searching and Transforming Commands, Creating Reports, Dashboards and Visualizations. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Splunk SPLK-1001 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.