Sample questions
Splunk Core Certified Advanced Power User (SPLK-1004) (SPLK-1004) practice questions
What is the result of 'transaction' command compared to 'stats'?
When creating a calculated field, what does the 'EVAL-' prefix in props.conf indicate?
You have a field 'ip_address' and want to tag it with 'internal' for specific subnets. What is the most efficient way to manage this?
When using the 'inputfields' parameter in a lookup definition, what happens?
Which configuration file would you modify to assign a tag to a field-value pair manually?
You defined a lookup that is not working. You verified the CSV exists and the app permissions are correct. What search-time troubleshooting step should you perform?
Which of the following best describes the difference between an event type and a tag?
Which TWO of the following are valid lookup types?
How do you extract a portion of a string using 'eval'?
Which THREE of the following items are configured in props.conf?
You have configured an automatic lookup that is failing to populate. You verified the lookup definition and the automatic lookup rule. What is the most likely reason for the failur…
You have a field 'status' that contains numerical codes. You want to create a field 'status_desc' that maps these codes to human-readable text. What is the recommended tool?
What is the effect of the 'overwrite' setting in a lookup configuration?
Which THREE of the following are benefits of using calculated fields?
You have a macro that uses a search command that is not allowed by the user's role. What happens when the user tries to run the macro?
When configuring a field alias in props.conf, which of the following is true?
Which THREE of the following are valid ways to manage Search Macros in Splunk?
Which TWO of the following are valid ways to create field extractions?
What is the primary benefit of creating an Event Type?
You want to filter out events where the 'action' field is empty. Which command is best?
What is the result of applying multiple aliases to the same field?
You are configuring a field lookup that needs to execute automatically for every search on a specific sourcetype. Where is the most appropriate place to configure this?
Where can you define an event type?
How can you view all existing field aliases in the Splunk Web interface?