SPLK-1002 Advanced Visualization and Lookups Practice Question
A dashboard panel uses a timechart to show error counts over time. Users report that the time range picker does not affect the panel. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The search uses a fixed earliest and latest time.
If the search uses fixed earliest/latest times (e.g., via `earliest=-30d@d` or a set time range in the search string), the time range picker has no effect. Option A is incorrect because sharing the dashboard does not affect time range behavior. Option B is incorrect because 'stats' can still respect the time range if used correctly, but the issue here is fixed time bounds, not the command. Option C is incorrect because an index that is not time-based would prevent any time-based search from working, but the panel would show no data or an error, not simply ignore the time picker.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The dashboard is not shared.
Why it's wrong here
The dashboard sharing setting does not affect how the time range picker interacts with panels.
- ✗
The panel uses 'stats' instead of 'timechart'.
Why it's wrong here
Using 'stats' instead of 'timechart' is not the cause; even a 'timechart' search can have fixed time bounds. The command type is irrelevant.
- ✗
The index is not time-based.
Why it's wrong here
If the index were not time-based, the panel would likely show no results or an error, but the time picker would still be ignored because the search has fixed times.
- ✓
The search uses a fixed earliest and latest time.
Why this is correct
Correct. When the search uses explicit earliest and latest parameters (e.g., `earliest=-1h@h latest=now`), the time range picker is overridden.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SPLK-1002 question from scratch — 475 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SPLK-1002 practice question is part of Courseiva's free Splunk certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SPLK-1002 exam.