Courseiva

SPLK-1004 · domain

Field Management And Calculated Fields

Practise Splunk Core Certified Advanced Power User (SPLK-1004) (SPLK-1004) Field Management And Calculated Fields practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

32 questions10 easy11 medium11 hard

Focused practice

Practice Field Management And Calculated Fields questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Field Management And Calculated Fields

IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.

IPv6 address types and their scopes (link-local, global unicast, multicast, ULA).

SLAAC vs DHCPv6 vs stateful assignment.

Neighbor Discovery Protocol replacing ARP.

IPv6 routing differences and dual-stack coexistence.

Watch out for

Common Field Management And Calculated Fields exam traps

  • Link-local addresses are not routable beyond the local link.
  • SLAAC uses EUI-64 or random interface IDs — not a DHCP server.
  • NDP uses ICMPv6, not ARP.
  • An IPv6 prefix is /64 for most host subnets, not /24.

Question index

All Field Management And Calculated Fields questions (32)

Click any question to see the full explanation, or start a practice session above.

1

When creating a calculated field, what does the 'EVAL-' prefix in props.conf indicate?

Hard
2

Which of the following is a requirement for using a CSV lookup?

Easy
3

Which TWO of the following are steps required to configure a CSV lookup?

Medium
4

What is the purpose of the 'tags.conf' file?

Medium
5

Which configuration file would you modify to assign a tag to a field-value pair manually?

Hard
6

Which TWO of the following are true about Tags?

Easy
7

You defined a lookup that is not working. You verified the CSV exists and the app permissions are correct. What search-time troubleshooting step should you perform?

Hard
8

Which THREE of the following are valid ways to search for a tag named 'production'?

Easy
9

You want to create a lookup that updates automatically as new data arrives. Which feature should you use?

Hard
10

When configuring a field alias in props.conf, which of the following is true?

Hard
11

What is the result of applying multiple aliases to the same field?

Medium
12

Which THREE of the following are common issues that cause a lookup to fail?

Hard
13

What is the effect of the 'overwrite' setting in a lookup configuration?

Hard
14

Which THREE of the following items are configured in props.conf?

Hard
15

What is the primary benefit of creating an Event Type?

Easy
16

How can you view all existing field aliases in the Splunk Web interface?

Easy
17

You need to create a persistent field mapping that allows users to search for 'user_id' instead of 'uid' without modifying the underlying raw data. Which feature should you use?

Easy
18

You want to create a calculated field that multiplies 'price' by 'tax_rate'. Why should you avoid using a field alias for this?

Medium
19

Which THREE of the following are standard configuration files for field management?

Hard
20

Which THREE of the following are benefits of using calculated fields?

Medium
21

Which TWO of the following are valid lookup types?

Medium
22

Where can you define an event type?

Easy
23

Which of the following is true about field extractions?

Easy
24

Which THREE of the following are true regarding the order of operations for search-time field extractions?

Hard
25

A user complains that a calculated field is not showing up. Which of the following is the best first step to troubleshoot?

Medium
26

You have a calculated field that performs a complex regex extraction and math calculation. When a user searches, the calculation is not appearing. What is the most likely cause?

Medium
27

Which TWO of the following are valid ways to create field extractions?

Easy
28

You are configuring a field lookup that needs to execute automatically for every search on a specific sourcetype. Where is the most appropriate place to configure this?

Hard
29

Which of the following best describes the difference between an event type and a tag?

Easy
30

You have a field 'status' that contains numerical codes. You want to create a field 'status_desc' that maps these codes to human-readable text. What is the recommended tool?

Medium
31

You have a field 'ip_address' and want to tag it with 'internal' for specific subnets. What is the most efficient way to manage this?

Medium
32

When using the 'inputfields' parameter in a lookup definition, what happens?

Medium

Frequently asked questions

What does the Field Management And Calculated Fields domain cover on the SPLK-1004 exam?
IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.
How many questions are in this domain?
This page lists all 32 Field Management And Calculated Fields questions in the SPLK-1004 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Field Management And Calculated Fields questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
splunk-adv-power SPLUNK-ADV-POWER field management and calculated fields Practice Questions