Splunk Core Certified Advanced Power User Free Sample Questions

20 free sample questions188 in the full practice test

Try simulator

SPLK-1004 Sample Questions

  1. Question 1

    A financial services firm has a critical fraud detection dashboard that monitors real-time transactions. The primary panel, which identifies suspicious transaction volumes per user, is experiencing significant performance degradation. The panel is powered by the following inline search:

    index=transactions earliest=-15m | stats count by user_id | where count > 100

    This search is one of five similar high-frequency searches on the same dashboard, all querying the transactions index. The dashboard must refresh every 5 minutes with data no more than 15 minutes old. The CISO has mandated that the dashboard's load time must not exceed 10 seconds. Given the high volume of transaction data, which approach offers the most efficient and scalable solution to meet these requirements?

    Answer and explanation

    Correct answer: B

    The most efficient solution is to use a base search with post-processing. A single base search retrieves the raw data once, and its results are cached. Each panel's post-process search then runs against this small, cached result set, which is significantly faster than each panel running a full search against the entire index. This design pattern minimizes the load on the indexers and dramatically improves dashboard performance, especially when multiple panels query the same base data.

  2. Question 2

    A security analyst is investigating user session activity from VPN logs. They need to group events into transactions based on a unique session_id. A session begins with an event containing action=login and ends with action=logout. However, some sessions are interrupted and do not have a logout event. The analyst wants to group all events for each session and identify which sessions are complete (have both login and logout). Which search is the MOST efficient and accurate way to achieve this?

    Answer and explanation

    Correct answer: B

    Using the stats command is significantly more performant than transaction for this type of grouping. stats is a transforming command that operates efficiently on the indexers. It can group by session_id, capture the start and end times, and list all actions. A subsequent eval command can then easily check for the presence of 'logout' in the multivalued actions field to determine if the session is complete. The transaction command is much more resource-intensive as it involves stateful processing on the search head.

  3. Question 3

    Multiple answers

    A data architect is designing a solution to enrich incoming web logs. The requirements are to add user-friendly product names, check IP addresses against a frequently updated list of malicious actors, and append the physical location of the server based on its hostname. Which lookup types should be used to meet these requirements? (Select THREE)

    Answer and explanation

    Correct answers: A, B, E

    A CSV lookup is ideal for static or infrequently changing data, such as mapping product IDs to their names. It's simple to manage and efficient for this purpose.

    The KV Store is the best choice for data that is frequently updated, such as a threat intelligence feed of malicious IPs. It allows for programmatic updates via REST API without needing to upload new files, making it highly suitable for dynamic data.

    An external (scripted) lookup is required to interface with an external system like a live inventory database in real-time. This provides the most current location data based on the server's hostname.

  4. Question 4

    An analyst needs to create a high-performance report from an accelerated data model named Network_Traffic. The goal is to find the total bytes sent from the top 5 src_ip addresses to any dest_ip in the 10.0.0.0/8 subnet, but only for events that occurred outside of business hours (5 PM to 9 AM). Which tstats search will accomplish this most effectively?

    Answer and explanation

    Correct answer: D

    This is the correct and most performant query. It uses tstats to query the accelerated data directly. summariesonly=true ensures only the accelerated data is used. It correctly filters by CIDR notation for dest_ip and uses the indexed date_hour field for efficient time filtering. Finally, it groups by src_ip and uses | sort 5 -total_bytes which is a highly efficient way to get the top 5 results without needing a subsequent head command.

  5. Question 5

    An e-commerce company logs the sequence of pages a user visits in a single event, with the page IDs stored in a multivalued field named page_sequence. An analyst needs to find the average time spent on each page by calculating the time difference between consecutive page views for each session. The raw event also contains a multivalued field timestamp_sequence with the epoch time of each page view. Which search correctly calculates the average time per page transition?

    Answer and explanation

    Correct answer: B

    This query correctly solves the problem by first using zip to combine the parallel multivalued fields into a single field. mvexpand then creates a separate event for each page view in the session. streamstats is used to get the timestamp of the previous event within the same session (by session_id). Finally, eval calculates the duration, and stats computes the average duration per page. This is the standard and correct pattern for analyzing sequences within multivalued fields.

  6. Question 6

    True or False: To optimize a search that filters events before performing a transformation, you should place filtering commands like where or search after transforming commands like stats or timechart.

    Answer and explanation

    Correct answer: B

    The statement is false. A fundamental Splunk search optimization principle is to filter data as early as possible. Filtering commands should be placed before transforming commands to reduce the number of events that the resource-intensive transforming command needs to process. This significantly improves search performance.

  7. Question 7

    A systems administrator is analyzing performance logs for different application services. They want to add a new field to each event, cpu_percentile, which shows the percentile rank of that event's cpu_usage compared to all other events for the same service. Which search correctly calculates and appends this per-event percentile?

    Answer and explanation

    Correct answer: C

    The eventstats command is the correct choice because it calculates a statistical result (like percentile) across a dataset and appends that result to every event without altering the original event structure. By using by service, it calculates the percentile within each service group and adds the cpu_percentile field to each corresponding event. stats would remove the original events, and streamstats would calculate a running percentile, which is not what was requested.

    pie title CPU Usage Distribution by Service "Service A" : 40 "Service B" : 25 "Service C" : 35

  8. Question 8

    An analyst is working with unstructured log data that contains key-value pairs in the format [key: value]. A single event can have multiple such pairs. An example is [user: admin] [action: login_failed] [reason: bad_password]. Which rex command is the most efficient and robust for extracting all keys and their corresponding values from the _raw field?

    Answer and explanation

    Correct answer: D

    While rex could work, Splunk provides a more specialized and efficient command, kvform, for exactly this type of extraction. kvform is designed to extract key-value pairs from structured text formats. This approach is more robust and performant than a general-purpose regex because it's optimized for this specific task and doesn't require crafting a complex regex pattern. It correctly defines the delimiters and will extract all pairs present in the event.

  9. Question 9

    A dashboard developer has created a form with two dropdown inputs: region and host. The host dropdown should dynamically populate with hosts from the selected region. The developer observes that the host dropdown remains empty after a region is selected. What is the most likely cause of this issue in the dashboard's Simple XML?

    Answer and explanation

    Correct answer: C

    For cascading inputs to work, the search for the dependent input (host) must use the token set by the parent input (region). The most common error is that the search populating the host dropdown does not filter based on the selected region token (e.g., $tok_region$). Without this filter, the search doesn't know how to narrow down the host list. The handler on the region input is necessary to trigger the update, but the host search itself must be correctly configured to use the token.

  10. Question 10

    An analyst has written the following search to find web servers that have experienced both a 404 error and a 503 error. The search is performing poorly due to the large number of errors.

    index=web [search index=web status=404 | dedup host | fields host] [search index=web status=503 | dedup host | fields host]

    Which of the following is the most performant and functionally equivalent alternative to this search?

    Answer and explanation

    Correct answer: C

    This is the most performant alternative. Using multiple subsearches or a join is very inefficient. This stats-based approach filters for all relevant events in a single pass (status=404 OR status=503), then uses stats dc(status) by host to count the number of unique statuses for each host. A final where status_count=2 filters this small statistical result set to only the hosts that have experienced both types of errors. This avoids the overhead of subsearches and is a core optimization pattern.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 188 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon