SPLK-1004 Sample Questions

SPLK-1004 Sample Questions & Answers

Statistical analysis commands tie with report and summary acceleration for the top share, next to deeper lookup options including the KV Store, regex-based field extraction, data model acceleration, subsearches, and building dashboards with forms and drilldowns.

Launch the full SPLK-1004 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Using Search Efficiently · Command ordering

    True or False: To optimize a search that filters events before performing a transformation, you should place filtering commands like where or search after transforming commands like stats or timechart.

    Show answer & explanation

    Correct answer: B

    The statement is false. A fundamental Splunk search optimization principle is to filter data as early as possible. Filtering commands should be placed before transforming commands to reduce the number of events that the resource-intensive transforming command needs to process. This significantly improves search performance.

  2. Question 2Intermediate

    Exploring Statistical Commands · Using eventstats

    A systems administrator is analyzing performance logs for different application services. They want to add a new field to each event, cpu_percentile, which shows the percentile rank of that event's cpu_usage compared to all other events for the same service. Which search correctly calculates and appends this per-event percentile?

    Show answer & explanation

    Correct answer: C

    The eventstats command is the correct choice because it calculates a statistical result (like percentile) across a dataset and appends that result to every event without altering the original event structure. By using by service, it calculates the percentile within each service group and adds the cpu_percentile field to each corresponding event. stats would remove the original events, and streamstats would calculate a running percentile, which is not what was requested.

    pie title CPU Usage Distribution by Service "Service A" : 40 "Service B" : 25 "Service C" : 35

  3. Question 3Intermediate

    Advanced Field Creation and Management · Performing search time field extraction using the erex and rex

    An analyst is working with unstructured log data that contains key-value pairs in the format [key: value]. A single event can have multiple such pairs. An example is [user: admin] [action: login_failed] [reason: bad_password]. Which rex command is the most efficient and robust for extracting all keys and their corresponding values from the _raw field?

    Show answer & explanation

    Correct answer: D

    While rex could work, Splunk provides a more specialized and efficient command, kvform, for exactly this type of extraction. kvform is designed to extract key-value pairs from structured text formats. This approach is more robust and performant than a general-purpose regex because it's optimized for this specific task and doesn't require crafting a complex regex pattern. It correctly defines the delimiters and will extract all pairs present in the event.

  4. Question 4Intermediate

    Using Forms · Create cascading inputs

    A dashboard developer has created a form with two dropdown inputs: region and host. The host dropdown should dynamically populate with hosts from the selected region. The developer observes that the host dropdown remains empty after a region is selected. What is the most likely cause of this issue in the dashboard's Simple XML?

    Show answer & explanation

    Correct answer: C

    For cascading inputs to work, the search for the dependent input (host) must use the token set by the parent input (region). The most common error is that the search populating the host dropdown does not filter based on the selected region token (e.g., $tok_region$). Without this filter, the search doesn't know how to narrow down the host list. The handler on the region input is necessary to trigger the update, but the host search itself must be correctly configured to use the token.

  5. Question 5Beginner

    Using Subsearches · When NOT to use subsearch

    An analyst has written the following search to find web servers that have experienced both a 404 error and a 503 error. The search is performing poorly due to the large number of errors.

    index=web [search index=web status=404 | dedup host | fields host] [search index=web status=503 | dedup host | fields host]

    Which of the following is the most performant and functionally equivalent alternative to this search?

    Show answer & explanation

    Correct answer: C

    This is the most performant alternative. Using multiple subsearches or a join is very inefficient. This stats-based approach filters for all relevant events in a single pass (status=404 OR status=503), then uses stats dc(status) by host to count the number of unique statuses for each host. A final where status_count=2 filters this small statistical result set to only the hosts that have experienced both types of errors. This avoids the overhead of subsearches and is a core optimization pattern.

  6. Question 6Intermediate

    Exploring eval Command Functions · Using comparison and conditional functions

    A financial analyst is working with transaction logs where currency amounts are logged in various formats (e.g., "USD 1,234.56", "EUR 987.65", "JPY 150000"). They need to create a new field named amount_usd that standardizes all amounts into US dollars, assuming the following fixed exchange rates: 1 EUR = 1.1 USD, 1 JPY = 0.007 USD. The new field should be a numeric type for calculations. Which eval expression correctly performs this conversion?

    Show answer & explanation

    Correct answer: B

    This is the correct approach. It first creates a clean numeric field numeric_amount by stripping all non-digit and non-decimal point characters. Then, it uses the case function to apply the correct conversion factor based on the currency symbol found in the original raw_amount field. This multi-step process is robust and handles the data cleaning and conditional logic correctly. The tonumber function ensures the final field is numeric.

  7. Question 7Intermediate

    Exploring Alerts · Using a webhook alert action

    A DevOps team wants to integrate Splunk alerts with their custom incident management system via a webhook. The system requires a JSON payload with a specific structure. The alert should trigger when more than 10 critical errors are detected in 5 minutes. Which configuration for a webhook alert action will correctly send the total error count and a list of the top 3 affected services to the endpoint?

    Show answer & explanation

    Correct answer: D

    This is the most appropriate configuration. The search ... | stats count, values(service) as affected_services aggregates the total count and collects the names of the services. The alert condition search count > 10 correctly triggers the alert based on the aggregated count. The webhook payload {"total_errors": $result.count$, "top_services": $result.affected_services$} correctly uses the $result. $ token syntax to populate the JSON payload with the values from the single result row generated by the stats command. The quotes around the tokens are removed to ensure the values are inserted correctly as a number and an array.

  8. Question 8Beginner

    Working with Self-Describing Data and Files · Using the spath command

    An analyst is ingesting JSON data from a cloud API which contains nested information about virtual machine instances. A sample event is shown below:

    {"instanceId": "i-123", "region": "us-east-1", "tags": [{"key": "owner", "value": "alice"}, {"key": "project", "value": "apollo"}], "state": {"code": 16, "name": "running"}}

    Which SPL query correctly extracts the value of the 'project' tag into a field named project_name?

    Show answer & explanation

    Correct answer: B

    This is the correct syntax. The tags field is a JSON array. spath uses curly braces {} to denote array indexing, which is 0-based. The 'project' tag is the second element in the array, so its index is 1. The query then accesses the value key within that array element. tags{1}.value correctly navigates to the value "apollo".

  9. Question 9Advanced

    Advanced Search Macros · Using nested search macros

    A Splunk architect is creating a validation macro named validate_ip(1) that takes an IP address as an argument. The macro should return the input IP address only if it falls within a private IP range (10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16). Otherwise, it should return nothing. Which is the correct implementation for this macro?

    Show answer & explanation

    Correct answer: D

    This is the most direct and correct implementation. It takes the macro argument $ip_addr$ and assigns it to a temporary field validated_ip. The where command then filters the event stream. If the IP matches any of the private CIDR ranges, the event (and the validated_ip field) is passed through. If it doesn't match, the event is discarded. This effectively returns the IP only when it's valid, as required. This approach integrates seamlessly into a search pipeline.

  10. Question 10Intermediate

    Using Acceleration Options: Report & Summary · Identifying which reports qualify for acceleration

    True or False: A report can be accelerated if its search pipeline includes the streamstats command.

    Show answer & explanation

    Correct answer: B

    This statement is false. Report acceleration works by creating a summary of searches that contain transforming commands (like stats, chart, timechart, top). The streamstats command is a streaming command, not a transforming one. It calculates statistics on an event-by-event basis without transforming the entire result set. Because of this, searches containing streamstats do not qualify for report acceleration.

Ready for the real thing?

The full SPLK-1004 simulator has every exam-style question, timed mode, and instant scoring.