Courseiva

SPLK-1003 · domain

troubleshooting

Practise Splunk Enterprise Certified Admin (SPLK-1003) (SPLK-1003) troubleshooting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

202 questions44 easy92 medium66 hard

Focused practice

Practice troubleshooting questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about troubleshooting

troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common troubleshooting exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All troubleshooting questions (202)

Click any question to see the full explanation, or start a practice session above.

1

You need to ensure that a Heavy Forwarder filters out sensitive data before it reaches the Indexer. Which configuration file should be modified?

Medium
2

Which THREE of the following are true about the 'can_delete' capability?

Medium
3

A user inherits roles 'RoleA' and 'RoleB'. 'RoleA' has 'srchIndexesAllowed' set to 'index1' and 'RoleB' has it set to 'index2'. What indexes can the user access?

Hard
4

Which TWO of the following actions occur when a Splunk license violation is active?

Hard
5

You are configuring a new index for high-volume data. To optimize ingestion performance, where should you place the hot buckets?

Medium
6

Which THREE of the following are true regarding the configuration precedence of apps?

Hard
7

If a user creates a configuration in their 'user' directory, how does it compare in precedence to the 'app' directory?

Hard
8

You need to modify the default behavior of a Splunk application without editing the files inside the 'default' directory. Where should you create the override file?

Medium
9

A company is using a Trial license. How does this affect their ability to add more indexers?

Hard
10

Which configuration file is used to map LDAP groups to Splunk roles?

Medium
11

Which THREE of the following are true regarding license usage monitoring?

Medium
12

A bucket in the 'warm' state is currently locked. What process is likely happening?

Hard
13

You need to ensure that specific data is sent to a specific indexer using the outputs.conf file. Which stanza is used for this?

Medium
14

If you want to use SAML authentication, which component must be configured as the 'Service Provider'?

Hard
15

A Splunk administrator needs to identify how much data is being indexed across multiple indexers to ensure they do not exceed their daily license quota. Where should the admin look first?

Easy
16

Which THREE of the following information points are displayed on the License Master dashboard?

Medium
17

You are troubleshooting a parsing issue. You want to see the configuration file path that contributed a specific setting. What flag should you use with btool?

Medium
18

What is the impact of a license warning on data indexing?

Medium
19

Which file in the index directory contains the bucket's metadata?

Easy
20

Which TWO of the following are valid stanza types found in indexes.conf?

Medium
21

Which configuration file is used to define index-time field extractions and line-breaking rules?

Easy
22

When configuring an indexer to receive data on port 9997, you notice that the Splunkd process is failing to bind to the port. What is the most likely cause?

Medium
23

What is the default retention policy for the '_internal' index?

Easy
24

An administrator needs to move an existing index's raw data to a new storage location without losing searchability. What is the recommended approach?

Medium
25

Which user interface feature allows you to view the connectivity status of all forwarders reporting to an Indexer?

Easy
26

What is the impact of placing a forwarder in a license pool?

Medium
27

An administrator has configured a License Pool and assigned specific indexers to it. However, the indexers are still consuming from the 'default' pool. What is the most likely cause?

Hard
28

An administrator needs to ensure that users from an LDAP group 'Splunk_Power_Users' are automatically assigned the 'power' role in Splunk. Where is this mapping configured?

Medium
29

Which Splunk component is responsible for orchestrating the transition of buckets from warm to cold?

Easy
30

Which TWO of the following are true regarding Role Inheritance?

Medium
31

What happens if the License Master becomes unreachable?

Medium
32

Which THREE pieces of information can be obtained using the 'splunk fsck' command?

Hard
33

Which capability is exclusive to a Heavy Forwarder compared to a Universal Forwarder?

Easy
34

Which TWO of the following are valid ways to configure inputs on a Universal Forwarder?

Medium
35

What is the default port used by the Splunk Web interface?

Easy
36

When setting up a License Master in a distributed environment, what is the recommended practice for the License Master role?

Hard
37

You are troubleshooting a file input that is not being ingested. You have verified the file path. Which command-line tool can show you if the file is being tracked by the monitor input?

Hard
38

What happens to data when a bucket rolls to 'frozen'?

Easy
39

What is the effect of setting 'allow_debug' to false in a role?

Easy
40

Which command is used to restart the Splunk service after modifying configuration files?

Easy
41

Which TWO actions should be taken before manually moving an index to a new storage volume?

Medium
42

What is the effect of setting 'autoLBFrequency' in outputs.conf on a forwarder?

Hard
43

An administrator needs to change the default maximum size of an index. Which file should be modified?

Medium
44

You are troubleshooting an issue where a user cannot view a specific dashboard. The user has the 'user' role. What is the most likely cause?

Hard
45

What is the effect of setting 'TRANSFORMS-routing' in props.conf?

Medium
46

When configuring an index, which setting determines the directory where 'cold' buckets are stored?

Medium
47

Which capability is required for a user to see the 'Settings' menu in Splunk Web?

Easy
48

What is the effect of setting 'maxHotSpanSecs' to a very low value?

Medium
49

Where is the global configuration for Splunk Enterprise stored?

Easy
50

A Splunk administrator observes that the license master is reporting an 'indexer-slave' mismatch. Which configuration file should the admin check on the license slave?

Hard
51

Which of the following is a valid method to restart the Splunk service on a Linux system?

Easy
52

Which THREE types of bucket states exist in a healthy Splunk indexer?

Hard
53

Where are the local configuration files for an installed app located?

Easy
54

Which Splunk component is primarily responsible for parsing and indexing incoming data streams?

Easy
55

Which TWO of the following are true regarding the Splunk Free license?

Medium
56

Which protocol is the default used by Splunk Universal Forwarders to communicate with Indexers?

Medium
57

An administrator needs to install a new technology add-on on a standalone Search Head. Which menu path in Splunk Web is used to perform this action?

Easy
58

Which TWO items are contained within an 'authorize.conf' role stanza?

Medium
59

An administrator finds that search performance for a specific index is slow. What should they check regarding index buckets?

Hard
60

If you want to debug why a specific sourcetype is not applying, which btool command helps identify the configuration file responsible?

Hard
61

A Splunk admin wants to implement license pooling to ensure that certain indexers do not consume more than a fixed portion of the total license. What is the correct order of operations?

Hard
62

Which THREE of the following configurations can be performed in props.conf?

Hard
63

An administrator needs to identify which indexer is responsible for a license violation. Where should they check?

Hard
64

A Universal Forwarder is failing to send data to the Indexer. The indexer shows no incoming traffic. Where is the first place you should check for errors?

Medium
65

Which TWO of the following describe the 'admin' role?

Easy
66

A Splunk administrator has configured a Deployment Server to manage forwarders. Which file on the forwarder must be configured to establish communication with the Deployment Server?

Medium
67

A Universal Forwarder reports as 'missing' in the Deployment Server. What is the most common cause?

Medium
68

If a setting is defined in both $SPLUNK_HOME/etc/system/local/props.conf and $SPLUNK_HOME/etc/apps/my_app/default/props.conf, which one wins?

Hard
69

You need to modify the retention of a specific index without affecting others. Where should you make this change in a distributed environment?

Hard
70

Which THREE capabilities are typically assigned to a 'Power User'?

Hard
71

An administrator wants to ensure that a specific role cannot search over a time range greater than 24 hours. Where is this limit configured?

Hard
72

A user reports they cannot see data from a specific sourcetype after enabling a new input on the indexer. Which Splunk CLI command can you run on the indexer to verify if data is being ingested for that sourcetype?

Medium
73

You have configured a serverclass in serverclass.conf on the Deployment Server. Which action is required to ensure that the forwarders receive the new configuration?

Hard
74

Which TWO of the following are valid ways to define field extractions?

Medium
75

What is the purpose of the 'TIME_PREFIX' attribute in props.conf?

Medium
76

How can an administrator monitor failed login attempts for a specific user?

Medium
77

You have a Heavy Forwarder performing data routing. You need to send data to two different indexer clusters based on the sourcetype. How do you configure this?

Hard
78

Which TWO items are managed within the 'Access Controls' menu in Splunk Web?

Easy
79

What is the primary function of the Deployment Server?

Easy
80

An administrator needs to monitor a script output every 60 seconds. Which configuration in inputs.conf is correct for a scripted input?

Medium
81

Which THREE parameters must be exchanged between Splunk and an Identity Provider for SAML to work?

Hard
82

Which TWO locations are common places to check for configuration files on a Linux Splunk instance?

Easy
83

Which TWO of the following are true about Heavy Forwarders?

Medium
84

Which THREE of these represent common issues when troubleshooting LDAP authentication?

Hard
85

To monitor a network port using a Universal Forwarder, which stanza should be added to inputs.conf?

Medium
86

You have two identical stanzas in different configuration files with the same precedence. How does Splunk determine which one wins?

Hard
87

Which Splunk process is responsible for the actual indexing of data on the indexer?

Medium
88

Which file would you edit to change the TCP listening port for a Splunk Universal Forwarder?

Easy
89

You need to ensure that specific data is retained for 365 days. Which parameter in indexes.conf controls this?

Medium
90

Which TWO of the following are true about 'local' versus 'default' directories?

Medium
91

Which TWO of the following directories are used to store Splunk configuration files?

Medium
92

Which TWO settings are required to enable cold-to-frozen archiving?

Medium
93

Which TWO of the following are valid ways to authenticate users in Splunk?

Medium
94

You need to create a new user account and assign them to the 'power' role. Which interface provides the most direct way to do this?

Medium
95

If you need to change the logging level of a specific component on a Universal Forwarder, which file should you edit?

Medium
96

Which user account is created by default and intended for administrative use, which should have its default password changed immediately?

Medium
97

Which Splunk component should be used to distribute configuration files to a large fleet of Universal Forwarders?

Medium
98

If a user is assigned two roles, 'RoleA' and 'RoleB', and 'RoleA' has 'rtsearch' enabled while 'RoleB' has 'rtsearch' disabled, what is the user's effective capability for real-time searches?

Hard
99

Which TWO directories are part of the standard Splunk configuration file precedence hierarchy?

Medium
100

What is the purpose of the 'srchFilter' attribute in a role definition?

Medium
101

Which TWO of the following are true about the 72-hour grace period?

Hard
102

You have a deployment server managing 500 Universal Forwarders. You need to update a specific app for only 50 of them based on OS type. How should you organize the deployment?

Hard
103

What happens to Splunk search capabilities when the license limit is reached for the first time in a 30-day period?

Easy
104

Which THREE of the following represent true statements about the 'transforms.conf' file?

Hard
105

What happens to a local user account if the underlying LDAP group they belong to is deleted?

Medium
106

Which of the following is a primary reason to choose a Heavy Forwarder over a Universal Forwarder?

Easy
107

Which THREE of the following actions can be performed from the 'Settings' menu in Splunk Web?

Medium
108

Which TWO of the following locations are valid for placing a custom 'inputs.conf' file?

Easy
109

Which THREE items are included in a bucket's directory?

Hard
110

A company is migrating from an Enterprise license to a Free license. What is the most significant functional impact on their Splunk deployment?

Medium
111

When using the 'monitor' stanza in inputs.conf, what does the 'followTail' attribute do?

Medium
112

An administrator wants to see a daily breakdown of license usage for the last 30 days. Which view is most appropriate?

Easy
113

You have defined a setting in $SPLUNK_HOME/etc/system/local/inputs.conf and the same setting exists in $SPLUNK_HOME/etc/apps/my_app/local/inputs.conf. Which value takes precedence?

Medium
114

Which TWO settings are commonly required when configuring an LDAP strategy?

Medium
115

Which TWO settings in indexes.conf are used to control the rotation of hot buckets?

Medium
116

Which TWO of the following are true regarding the configuration of multiple license pools?

Hard
117

Which THREE of the following are components of a standard Splunk architecture?

Hard
118

You need to ensure that an index does not exceed 500GB of total disk space. Which configuration setting in indexes.conf should you modify?

Medium
119

You notice that data is being indexed with the wrong timestamp. Which configuration file is used to specify timestamp extraction rules?

Medium
120

You need to ensure that Data Models are accelerated. Where are the acceleration summaries stored?

Medium
121

What is the maximum number of license violations allowed in a 30-day period before search is blocked?

Medium
122

What is the consequence of having the same 'serverName' in server.conf for two different Universal Forwarders?

Hard
123

If a user is assigned to a role that does not have the 'license_tab' capability, what will they see in the Settings menu?

Medium
124

Which TWO methods can be used to monitor the disk usage of an index?

Medium
125

You are deploying a Universal Forwarder to a Windows server that must monitor local Event Logs and send them to an Indexer. Which component is required to handle the parsing of these logs before they are forwarded?

Medium
126

When using the 'splunk cmd splunkd bucket-info' tool, what are you primarily investigating?

Medium
127

After installing a new app, you notice that the app's dashboards are not appearing in the user's view. What is the first thing you should check?

Easy
128

You are configuring SAML authentication and need to map the 'email' attribute from the Identity Provider to the Splunk 'realName' field. Where do you configure this?

Hard
129

What is the default role assigned to a new user account if no other role is specified?

Easy
130

You have a distributed environment. You need to ensure that specific knowledge objects (saved searches) created on a Search Head are available to all other Search Heads. What is the recommended way to handle this?

Hard
131

Which THREE actions occur when a Universal Forwarder is added to a Deployment Server?

Hard
132

Which TWO of the following settings are typically found in inputs.conf?

Medium
133

Which file is responsible for defining how data is rotated in an index?

Easy
134

What happens to a user's session if their role is modified while they are logged in?

Easy
135

Which TWO of the following are valid ways to resolve a license violation?

Hard
136

A user reports that their search is failing to return data from 3 years ago, even though the retention policy is set to 5 years. What is the most likely cause?

Hard
137

Which THREE of the following are valid components of a Splunk license configuration?

Medium
138

You need to restrict a specific user role from searching a particular index. Where is this configuration defined?

Hard
139

Which Splunk GUI page provides a summary of all configured indexes and their current disk usage?

Easy
140

Which THREE of the following are true regarding the behavior of 'btool'?

Hard
141

You need to restrict a specific user from accessing the 'internal' index even though their assigned role has access to all indexes. How do you implement this restriction?

Medium
142

Which TWO of the following are required to successfully add an indexer to a license pool?

Hard
143

What is the purpose of the 'disabled=1' attribute in an inputs.conf stanza?

Medium
144

Which stanza is required in props.conf to identify a sourcetype?

Medium
145

How does Splunk handle configuration files that are missing a required attribute?

Hard
146

When a Splunk license violation occurs, how long does the warning period last before search is blocked?

Medium
147

Which THREE of the following items are considered 'license slaves'?

Medium
148

An administrator needs to increase the number of search results displayed in a dashboard panel. Where can this limit be adjusted?

Medium
149

What is the primary function of the 'thawed' bucket state?

Medium
150

An administrator needs to move the License Master from one server to another. What is the most critical step?

Hard
151

You need to enable multi-factor authentication (MFA) for your Splunk instance. Where is this usually integrated?

Medium
152

An administrator needs to monitor a local text file on a Windows server and send the data to a Splunk indexer. Which component is the most efficient choice for this task?

Easy
153

When should you use the 'volume' configuration in indexes.conf?

Medium
154

If a search head cluster member cannot access an indexer's bucket, what should you verify first?

Hard
155

You need to ensure that a Universal Forwarder continues to collect data during a network outage between the forwarder and the indexer. Which feature should be enabled in outputs.conf?

Hard
156

When using transforms.conf to extract fields, what is the 'SOURCE_KEY' setting used for?

Medium
157

Which TWO of the following are true regarding the Deployment Server?

Hard
158

Which THREE of the following items are considered Knowledge Objects in Splunk?

Easy
159

What is the primary function of the 'Indexer Cluster' feature?

Easy
160

Which menu path in Splunk Web is used to manage existing user roles?

Easy
161

What happens if you have a syntax error in a .conf file?

Hard
162

To ensure a Universal Forwarder is using the correct index, where is the 'index' attribute defined?

Easy
163

If you want to move the index data directory to a new partition, what setting in indexes.conf must be updated?

Hard
164

Which of the following is a 'capability' in Splunk?

Easy
165

Which TWO of the following are valid ways to monitor the status of a Splunk instance?

Medium
166

Which TWO components must be configured on a Universal Forwarder to ensure data reaches the Indexer?

Medium
167

What is the purpose of the 'whitelist' and 'blacklist' attributes in a serverclass.conf file?

Medium
168

A customer wants to split their 1TB license into two 500GB pools for different departments. How is this achieved?

Hard
169

Which TWO factors contribute to the 'frozen' state of a bucket?

Medium
170

A user reports that a setting in props.conf is not being applied. You want to see the final merged configuration for a specific sourcetype on a specific host. Which tool should you use?

Easy
171

An administrator needs to manually move a bucket to frozen state immediately for compliance reasons. What is the best method?

Hard
172

Which THREE features are associated with Indexer Clustering?

Hard
173

Which file stores the definitions of roles and their associated capabilities?

Easy
174

Which TWO attributes in props.conf are commonly used to handle multiline events?

Medium
175

Where does an administrator configure the License Master URL for an indexer?

Easy
176

You are configuring a Heavy Forwarder to mask sensitive credit card information before the data reaches the indexer. Which configuration file must you modify to implement this data transformation?

Medium
177

You are troubleshooting a parsing issue where multiline events are not being grouped correctly. Where in the configuration files would you adjust the 'BREAK_ONLY_BEFORE' setting?

Hard
178

If you want to prevent a user from using the 'delete' command, which capability must be removed from their assigned role?

Medium
179

When using btool, what does the output show by default?

Hard
180

Which TWO of the following are true about the Universal Forwarder?

Medium
181

You are configuring a Universal Forwarder to send logs to an Indexer Cluster. Where should you define the outputs.conf file to ensure the forwarder correctly balances traffic across all indexers?

Medium
182

How can you increase the amount of raw data stored in a single bucket before it rolls?

Medium
183

Why might an administrator need to use the 'splunk edit licenser-localslave' command?

Medium
184

Which TWO of the following are true regarding Indexer Clustering?

Hard
185

Which TWO components are involved in managing Data Model acceleration?

Medium
186

An administrator wants to prevent events from a specific IP address from being stored in an index. Which file and stanza would you use for this indexing-time filter?

Hard
187

In props.conf, what does the 'REPORT-' prefix signify?

Medium
188

You want to prevent an index from growing beyond 10,000,000 events. Which setting is appropriate?

Hard
189

When configuring a Deployment Client, what must be defined in deploymentclient.conf?

Medium
190

You are troubleshooting a connection issue from a forwarder to an indexer. Which log file on the indexer would best show connection attempts from forwarders?

Hard
191

Which THREE attributes can be used in serverclass.conf to define target clients?

Hard
192

Which THREE configuration files are most critical for defining how data is ingested and parsed?

Hard
193

Which TWO settings in outputs.conf are recommended for load balancing data across multiple indexers?

Medium
194

When using a Heavy Forwarder to perform data masking, which stanza in transforms.conf is used to define the replacement regex?

Medium
195

What command is used to check the health and integrity of an index bucket?

Easy
196

Which of the following describes the purpose of a License Pool?

Easy
197

You are configuring a scripted input to run a python script. Where is the best location to store this script on a Universal Forwarder?

Hard
198

Which THREE factors can impact the performance of a Universal Forwarder?

Hard
199

You need to perform a regex-based routing operation to send data to different indexes based on the host. Which file must be configured to define the routing regex?

Medium
200

Which license type does not support license clustering?

Easy
201

How do you restart the Splunk service on a Linux-based Universal Forwarder?

Easy
202

When configuring 'LDAP Strategy', what is the purpose of the 'User Base DN'?

Hard

Frequently asked questions

What does the troubleshooting domain cover on the SPLK-1003 exam?
troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 202 troubleshooting questions in the SPLK-1003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only troubleshooting questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.