Sample questions
Splunk Core Certified Power User SPLK-1003 practice questions
In the CIM, which field is commonly used to identify the user responsible for an authentication event?
When creating a saved search that runs every hour and sends an email alert when the count of errors exceeds 10, which action must be configured in addition to the search logic?
An analyst wants to create a running total of sales per day over a week. The data has fields: date, sales. Which search would produce a cumulative sum for each day?
A search uses `transaction maxspan=30s maxpause=5s`. Events are sorted by _time. If there is a gap of 10 seconds between two events, what happens?
Refer to the exhibit. What is the purpose of the eval command in this search?
Match each Splunk index time field to its meaning.
A Splunk administrator needs to schedule a saved search to run every second Friday at 10:00 AM. Which cron expression should be used?
Which THREE of the following are benefits of using eventstats over stats when analyzing event logs? (Choose three.)
The exhibit shows a search to find the top 5 URI-method combinations by count. However, the results show only 5 rows, but the analyst expected to see the top 5 URIs overall, not co…
An analyst is using the transaction command to group events by a field that has high cardinality (millions of unique values). The search is taking too long and consuming too much m…
A Splunk admin wants to track the number of unique users who accessed a system each hour over the past 24 hours. Which search provides the correct result?
Which command creates a new field that contains the string 'high' if a numeric field exceeds 100, otherwise 'low'?
An analyst wants to identify the top 5 user agents that generated the most 404 errors in the last 24 hours. Which search accomplishes this correctly and efficiently?
A security analyst is using a lookup table to enrich IP addresses with threat intelligence. Which THREE statements about lookups are true?
A team uses a large index with many sourcetypes. They want to identify categories of events that have at least 100 occurrences, compute the average response_time per category, and…
A developer needs to calculate the 95th percentile of response times for each service over the past hour. The data has fields: service, response_time. Which search achieves this co…
A company uses `transaction` to group events by `order_id`. Some orders have many events (1000+). Which option should be added to prevent a single transaction from consuming too ma…
A security team needs to group all login events from the same user session. Events include 'login' and 'logout' with a common session_id field. Which command should be used to comb…
A Splunk administrator wants to create a reusable search component that accepts a sourcetype and a time range. What is the correct method to define this in Splunk?
Arrange the steps to create a knowledge object of type 'Event Type' in Splunk.
A dashboard is slow to load because it runs a search that uses `transaction` to group events into sessions. The search is `index=main source=web | transaction clientip maxspan=30m…
Order the steps to create a dashboard panel using the XML source editor in Splunk.
An organization has a transaction that groups firewall events by source IP to detect port scans. The transaction uses `maxpause=1m`. Some valid scans are being missed because event…
A user wants to find the number of unique users who logged in each day over the past week. Which SPL search should be used?