Courseiva
easyMultiple ChoiceObjective-mapped

SPLK-1001 Practice Question: A Splunk administrator for a large e-commerce…

You are a Splunk administrator for a large e-commerce company. The security team frequently runs searches against the web access logs (sourcetype=access_combined) to investigate suspicious activity. These searches often take 5-10 minutes to complete, and the team is frustrated. You decide to implement a data model to accelerate these searches. After creating a data model based on the CIM Web model and enabling acceleration for the 'Web' dataset, you notice that the acceleration summary size grows to over 50 GB and the rebuild process takes more than an hour every night, causing some searches to time out during the rebuild window. What is the most effective way to address this issue?

⚠ Common exam trap

Candidates often think customizing fields (Option B) is the best fix, but they overlook that the time range is the primary driver of summary size and rebuild time in high-volume environments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Reduce the acceleration time range from 'All time' to 'Last 7 days' to limit the summary size and rebuild duration.

Reducing the acceleration time range from 'All time' to a shorter window like 'Last 7 days' directly limits the amount of data the acceleration summary must cover. This shrinks the summary size (under 50 GB) and shortens the nightly rebuild time, preventing search timeouts during the rebuild window while still accelerating the most relevant recent data for security investigations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Increase the bucket size in the acceleration settings to reduce the number of buckets being rebuilt.

    Why it's wrong here

    Incorrect: Increasing bucket size would increase summary size and rebuild time, not decrease.

  • Create a custom data model that includes only the fields needed for security investigations and enable acceleration.

    Why it's wrong here

    Incorrect: This does not directly reduce summary size or rebuild time; it may still be large.

  • Reduce the acceleration time range from 'All time' to 'Last 7 days' to limit the summary size and rebuild duration.

    Why this is correct

    Correct: Limiting the acceleration range reduces both storage and rebuild time, still covering recent data.

  • Disable acceleration and instead rely on the security team to use more focused time ranges.

    Why it's wrong here

    Incorrect: This removes the acceleration benefit and does not solve the underlying performance issue.

About these practice questions

This SPLK-1001 question is part of Courseiva's 502-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SPLK-1001 practice question is part of Courseiva's free Splunk certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SPLK-1001 exam.