Splunk

SPLK-1002 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 151-question bank.

Provider
Splunk
Question bank
151
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for SPLK-1002, a certification listed under Splunk. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Splunk. The certification credential is issued by Splunk, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which of the following statements would help a user choose between the transaction and stats commands?

    Choose one answer.

    • stats can only group events using IP addresses.
    • The transaction command is faster and more efficient.
    • There is a 1000 event limitation with the transaction command.
    • Use stats when the events need to be viewed as a single correlated event.
  2. Question 2 · 1

    Which of the following is true about the Splunk Common Information Model (CIM)?

    Choose one answer.

    • The CIM contains 28 pre-configured datasets.
    • The data models included in the CIM are configured with data model acceleration turned on.
    • The data models included in the CIM are configured with data model acceleration turned off.
    • The CIM is an app that needs to run on the indexer.
  3. Question 3 · 1

    Consider the following search run over a time range of last 7 days: index=web sourcetype=access_combined | timechart avg(bytes) by product_name Which option is used to change the default time span so that results are grouped into 12 hour intervals?

    Choose one answer.

    • timespan=12
    • span=12h
    • timespan=12h
    • span=12
  4. Question 4 · 1

    When would transaction be used instead of stats?

    Choose one answer.

    • To have a faster and more efficient search.
    • To see results of a calculation.
    • To group events based on start/end values.
    • To group events based on a single field value.
  5. Question 5 · 1

    Given the following eval statement: ... | eval field1 = if(isnotnull(fieid1),field1,0), field2 = if(isnull Which of the following is the equivalent using fillnull?

    Choose one answer.

    • There is no equivalent expression using fillnull
    • ... | fillnull values=(0,"NO-VALUE") fields=(field1,field2)
    • ... | fillnull field1|' fillnull value="NO-VALUE" field2
    • ... | fillnull value=0 field1 | fillnull field2
  6. Question 6 · 1

    The Splunk Common Information Model (CIM) is a collection of what type of knowledge object?

    Choose one answer.

    • Saved searches
    • Lookups
    • KV Store
    • Data models
  7. Question 7 · 1

    How is a Search Workflow Action configured to run at the same time range as the original search?

    Choose one answer.

    • Select the "Use the same time range as the search that created the field listing" checkbox.
    • Set the earliest time to match the original search.
    • Select the same time range from the time-range picker.
    • Select the "Overwrite time range with the original search" checkbox.
  8. Question 8 · 1

    A calculated field is a shortcut for performing repetitive, long, or complex transformations using which of the following commands?

    Choose one answer.

    • transaction
    • eval
    • lookup
    • stats
  9. Question 9 · 1

    When using the transaction command, how are evicted transactions identified?

    Choose one answer.

    • _txn field is set to 1, or true.
    • open_txn field is set to l, or true.
    • max_txn field is set to 0, or false.
    • closed_txn field is set to 0, or false.
  10. Question 10 · 1

    How are arguments defined within the macro search string?

    Choose one answer.

    • “arg”
    • %arg%
    • $arg$
    • ‘arg’
  11. Question 11 · 1

    By default, how is acceleration configured in the Splunk Common Information Model (CIM) add-on?

    Choose one answer.

    • Turned off.
    • Turned on.
    • Determined automatically based on the sourcetype.
    • Determined automatically based on the data source.
  12. Question 12 · 1

    Which of the following objects can a calculated field use as a source?

    Choose one answer.

    • An alias of a field.
    • A field added by an automatic lookup.
    • The tag field.
    • The eventtype field.
  13. Question 13 · 1

    How are event types different from saved reports?

    Choose one answer.

    • Event types can be shared with Splunk users and added to dashboards.
    • Event types include formatting of the search results.
    • Event types do not include a time range.
    • Event types cannot be used to organize data into categories.
  14. Question 14 · 1

    When creating a data model, which root dataset requires at least one constraint?

    Choose one answer.

    • Root event dataset
    • Root transaction dataset
    • Root search dataset
    • Root child dataset
  15. Question 15 · 1

    Which search retrieves events with the event type web_errors?

    Choose one answer.

    • tag=web_errors
    • eventtype=web_errors
    • eventtype(web_errors)
    • eventtype "web_errors"

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free