SPLK-1004 Sample Questions & Answers
Statistical analysis commands tie with report and summary acceleration for the top share, next to deeper lookup options including the KV Store, regex-based field extraction, data model acceleration, subsearches, and building dashboards with forms and drilldowns.
Launch the full SPLK-1004 simulator →Free SPLK-1004 Sample Questions with Answers
Real questions from the Splunk Core Certified Advanced Power User practice test — answers and explanations included. Showing 10 of 20 free samples.
- Question 1
True or False: To optimize a search that filters events before performing a transformation, you should place filtering commands like
whereorsearchafter transforming commands likestatsortimechart.Show answer & explanation
Correct answer: B
The statement is false. A fundamental Splunk search optimization principle is to filter data as early as possible. Filtering commands should be placed before transforming commands to reduce the number of events that the resource-intensive transforming command needs to process. This significantly improves search performance.
- Question 2
A systems administrator is analyzing performance logs for different application services. They want to add a new field to each event,
cpu_percentile, which shows the percentile rank of that event'scpu_usagecompared to all other events for the sameservice. Which search correctly calculates and appends this per-event percentile?Show answer & explanation
Correct answer: C
The
eventstatscommand is the correct choice because it calculates a statistical result (like percentile) across a dataset and appends that result to every event without altering the original event structure. By usingby service, it calculates the percentile within each service group and adds thecpu_percentilefield to each corresponding event.statswould remove the original events, andstreamstatswould calculate a running percentile, which is not what was requested.pie title CPU Usage Distribution by Service "Service A" : 40 "Service B" : 25 "Service C" : 35 - Question 3
An analyst is working with unstructured log data that contains key-value pairs in the format
[key: value]. A single event can have multiple such pairs. An example is[user: admin] [action: login_failed] [reason: bad_password]. Whichrexcommand is the most efficient and robust for extracting all keys and their corresponding values from the_rawfield?Show answer & explanation
Correct answer: D
While
rexcould work, Splunk provides a more specialized and efficient command,kvform, for exactly this type of extraction.kvformis designed to extract key-value pairs from structured text formats. This approach is more robust and performant than a general-purpose regex because it's optimized for this specific task and doesn't require crafting a complex regex pattern. It correctly defines the delimiters and will extract all pairs present in the event. - Question 4
A dashboard developer has created a form with two dropdown inputs:
regionandhost. Thehostdropdown should dynamically populate with hosts from the selectedregion. The developer observes that thehostdropdown remains empty after aregionis selected. What is the most likely cause of this issue in the dashboard's Simple XML?Show answer & explanation
Correct answer: C
For cascading inputs to work, the search for the dependent input (host) must use the token set by the parent input (region). The most common error is that the search populating the host dropdown does not filter based on the selected region token (e.g.,
$tok_region$). Without this filter, the search doesn't know how to narrow down the host list. Thehandler on the region input is necessary to trigger the update, but the host search itself must be correctly configured to use the token. - Question 5
An analyst has written the following search to find web servers that have experienced both a 404 error and a 503 error. The search is performing poorly due to the large number of errors.
index=web [search index=web status=404 | dedup host | fields host] [search index=web status=503 | dedup host | fields host]Which of the following is the most performant and functionally equivalent alternative to this search?
Show answer & explanation
Correct answer: C
This is the most performant alternative. Using multiple subsearches or a
joinis very inefficient. Thisstats-based approach filters for all relevant events in a single pass (status=404 OR status=503), then usesstats dc(status) by hostto count the number of unique statuses for each host. A finalwhere status_count=2filters this small statistical result set to only the hosts that have experienced both types of errors. This avoids the overhead of subsearches and is a core optimization pattern. - Question 6
A financial analyst is working with transaction logs where currency amounts are logged in various formats (e.g., "USD 1,234.56", "EUR 987.65", "JPY 150000"). They need to create a new field named
amount_usdthat standardizes all amounts into US dollars, assuming the following fixed exchange rates: 1 EUR = 1.1 USD, 1 JPY = 0.007 USD. The new field should be a numeric type for calculations. Whichevalexpression correctly performs this conversion?Show answer & explanation
Correct answer: B
This is the correct approach. It first creates a clean numeric field
numeric_amountby stripping all non-digit and non-decimal point characters. Then, it uses thecasefunction to apply the correct conversion factor based on the currency symbol found in the originalraw_amountfield. This multi-step process is robust and handles the data cleaning and conditional logic correctly. Thetonumberfunction ensures the final field is numeric. - Question 7
A DevOps team wants to integrate Splunk alerts with their custom incident management system via a webhook. The system requires a JSON payload with a specific structure. The alert should trigger when more than 10 critical errors are detected in 5 minutes. Which configuration for a webhook alert action will correctly send the total error count and a list of the top 3 affected services to the endpoint?
Show answer & explanation
Correct answer: D
This is the most appropriate configuration. The search
... | stats count, values(service) as affected_servicesaggregates the total count and collects the names of the services. The alert conditionsearch count > 10correctly triggers the alert based on the aggregated count. The webhook payload{"total_errors": $result.count$, "top_services": $result.affected_services$}correctly uses the$result. $token syntax to populate the JSON payload with the values from the single result row generated by thestatscommand. The quotes around the tokens are removed to ensure the values are inserted correctly as a number and an array. - Question 8
An analyst is ingesting JSON data from a cloud API which contains nested information about virtual machine instances. A sample event is shown below:
{"instanceId": "i-123", "region": "us-east-1", "tags": [{"key": "owner", "value": "alice"}, {"key": "project", "value": "apollo"}], "state": {"code": 16, "name": "running"}}Which SPL query correctly extracts the value of the 'project' tag into a field named
project_name?Show answer & explanation
Correct answer: B
This is the correct syntax. The
tagsfield is a JSON array.spathuses curly braces{}to denote array indexing, which is 0-based. The 'project' tag is the second element in the array, so its index is1. The query then accesses thevaluekey within that array element.tags{1}.valuecorrectly navigates to the value "apollo". - Question 9
A Splunk architect is creating a validation macro named
validate_ip(1)that takes an IP address as an argument. The macro should return the input IP address only if it falls within a private IP range (10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16). Otherwise, it should return nothing. Which is the correct implementation for this macro?Show answer & explanation
Correct answer: D
This is the most direct and correct implementation. It takes the macro argument
$ip_addr$and assigns it to a temporary fieldvalidated_ip. Thewherecommand then filters the event stream. If the IP matches any of the private CIDR ranges, the event (and thevalidated_ipfield) is passed through. If it doesn't match, the event is discarded. This effectively returns the IP only when it's valid, as required. This approach integrates seamlessly into a search pipeline. - Question 10
True or False: A report can be accelerated if its search pipeline includes the
streamstatscommand.Show answer & explanation
Correct answer: B
This statement is false. Report acceleration works by creating a summary of searches that contain transforming commands (like
stats,chart,timechart,top). Thestreamstatscommand is a streaming command, not a transforming one. It calculates statistics on an event-by-event basis without transforming the entire result set. Because of this, searches containingstreamstatsdo not qualify for report acceleration.
Ready for the real thing?
The full SPLK-1004 simulator has every exam-style question, timed mode, and instant scoring.