Sample questions
Splunk Core Certified User SPLK-1002 practice questions
Drag and drop the steps to create a new Splunk index into the correct order.
You are a Splunk analyst for a financial services firm. You need to create a weekly report for management showing the total transaction value and number of transactions per day, br…
Creating Reports, Dashboards and VisualizationsmediumSee the answer and why each option is right or wrong →A Splunk administrator receives a complaint that a saved search is slow. The search uses a lookup to enrich events with a CSV file that has 500,000 rows. Which optimization is most…
Which THREE of the following statements about data model acceleration are true?
You are a Splunk administrator at a large e-commerce company. The operations team has created a real-time dashboard to monitor website performance. The dashboard includes multiple…
Creating Reports, Dashboards and VisualizationshardSee the answer and why each option is right or wrong →Refer to the exhibit. An admin sees that the Web_Traffic data model is accelerated but shows 'Summaries require rebuild'. What does this status indicate?
A team creates a dashboard that uses a drop-down input to select a server. The dashboard slows down significantly when the input changes. What is the most likely cause?
Creating Reports, Dashboards and VisualizationsmediumSee the answer and why each option is right or wrong →Refer to the exhibit. A security analyst runs a search to identify HTTP 500 errors over time. Which time period shows the highest count of 500 errors?
A large e-commerce company uses Splunk to monitor their web application. The operations team has noticed that the search for tracking user sessions is taking too long and consuming…
An analyst wants to compute the average response time for each server from web server logs. The field `response_time` is a string like '120ms'. What is the correct way to convert a…
A Splunk admin wants to enrich web server logs with geographic location data based on IP addresses. Which approach should they use?
A dashboard includes a single value visualization showing the total number of login failures. The number seems too high. Which common mistake could cause inflated counts?
Creating Reports, Dashboards and VisualizationseasySee the answer and why each option is right or wrong →A user wants to see the top 5 most common values of the 'action' field in the web access logs. Which command should be used?
Which of the following are true statements about using fields and lookups in Splunk? Choose all that apply. (There are four correct answers.)
A user creates a dashboard with multiple panels. Some panels share the same search. To improve performance, what should the user do?
Creating Reports, Dashboards and VisualizationsmediumSee the answer and why each option is right or wrong →A Splunk administrator notices that a new user cannot see any data in the Search & Reporting app, even though the user has the 'user' role. What is the most likely cause?
Which THREE of the following are valid uses of the 'eval' command? (Choose three.)
Which three of the following statements about lookup tables and their usage in Splunk are correct? (Choose three.)
Which TWO of the following are valid ways to share a Splunk dashboard?
Which of the following are components of the Splunk interface that can be used to refine and focus search results? (Choose all that apply. There are four correct answers.)
A team uses a lookup to map IP addresses to geographic locations. The lookup is large and updated weekly. Which lookup type is best suited?
Which of the following is a default field that is automatically extracted by Splunk?
Which TWO of the following commands can be used to create a new field from existing fields?
Basic Searching and Transforming CommandsmediumSee the answer and why each option is right or wrong →Which of the following is the default time range in a new Splunk search?