Courseiva
Question 351 of 502
mediumMatchingObjective-mapped

SPLK-1001 Practice Question: Match each data input type to its description.

Match each data input type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Tails a file or directory for new data

Receives syslog data via UDP or TCP

Runs a script to collect data

Receives data via HTTP or HTTPS

Collects Windows Event Log data

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Monitor input: Reads data from files and directories, following any changes.

The correct matches are: Monitor input tracks file changes; HTTP Event Collector receives data over HTTP/HTTPS. Confusion often arises between Monitor and Network inputs, and between HEC and Scripted inputs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Monitor input: Reads data from files and directories, following any changes.

    Why this is correct

    This correctly describes the Monitor input type used for tracking file changes.

  • Monitor input: Accepts data over TCP or UDP ports.

    Why it's wrong here

    Incorrect — this describes Network input (TCP/UDP), not Monitor input.

  • HTTP Event Collector: Receives data via HTTP or HTTPS.

    Why this is correct

    Correctly defines the HTTP Event Collector input type.

  • HTTP Event Collector: Executes a script to gather data.

    Why it's wrong here

    Incorrect — this describes Scripted input, not HTTP Event Collector.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SPLK-1001

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Drag and drop the steps to add a new data input using Splunk Web (e.g., monitor a log file) into the correct order.

medium
  • A.Select data input type, then specify source, then configure metadata
  • B.Specify source, then configure metadata, then select data input type
  • C.Select data input type, then configure metadata, then specify source
  • D.Configure metadata, then select data input type, then specify source

Why A: Adding a data input involves selecting the type, specifying the source, and configuring metadata.

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SPLK-1001 practice question is part of Courseiva's free Splunk certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SPLK-1001 exam.