SPLK-1001 Splunk Basics and Interface Navigation Practice Question
A company has 50 Splunk users in the default 'user' role. The Splunk administrator wants to allow a subset of 5 users to create custom alerts and reports, but not modify data inputs or indexes. The administrator creates a new role called 'analyst' and assigns the 'can_create_alerts' and 'can_create_reports' capabilities. However, when these 5 users log in, they cannot create alerts or reports and receive an error that they 'do not have permission to create alerts'. The administrator verifies that the role has both capabilities. Which of the following is the most likely cause and solution?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The 'analyst' role may not be correctly assigned to the 5 users. Verify that the users are members of the 'analyst' role and that no conflicting restrictions are blocking the capabilities.
In Splunk, user permissions are the union of capabilities from all assigned roles. The default 'user' role lacks alert/report creation capabilities, but the new 'analyst' role explicitly grants them. With both roles assigned, the users should effectively have the creation capabilities. Since they still receive a permission error, the most likely cause is that the 'analyst' role is not correctly assigned to those 5 users, or another restriction is overriding the capabilities. Verify role assignment and ensure no conflicting limitations exist. The other options are incorrect because: Option A is unnecessary (creating alerts/reports does not require 'edit_search'); Option B would grant creation to all 50 users, not just the subset; Option C is a post-creation configuration, not a prerequisite for creating alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The 'analyst' role lacks the 'edit_search' capability. Add it to the role.
Why it's wrong here
The error mentions permissions to create alerts, not search.
- ✗
The administrator must grant the 'can_create_alerts' capability to the 'user' role.
Why it's wrong here
That would give all 50 users the capability, which is not desired.
- ✗
The administrator must configure an alert action (e.g., email) before alerts can be created.
Why it's wrong here
Alert actions are configured within alerts, not a prerequisite for creation.
- ✓
The 'analyst' role may not be correctly assigned to the 5 users. Verify that the users are members of the 'analyst' role and that no conflicting restrictions are blocking the capabilities.
Why this is correct
Users must have a role with the capabilities; if they have multiple roles, capabilities are union, but removal of default role may be needed.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SPLK-1001 question from scratch — 502 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SPLK-1001 practice question is part of Courseiva's free Splunk certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SPLK-1001 exam.