SPLK-1005 Sample Questions & Answers
Getting data into the cloud service ties with configuring monitor inputs for the heaviest weight, next to network and scripted inputs, parsing and data preview, manipulating raw data, cloud topology basics, forwarder management, and working with cloud support.
Launch the full SPLK-1005 simulator →Showing 10 of 20 free samples.
- Question 1IntermediateSelect 2
Network and Other Inputs · Use the HTTP Event Collector (HEC) to get data into Splunk
An e-commerce company uses the Splunk HTTP Event Collector (HEC) to ingest transaction data from a microservice. To ensure data is routed to the correct index and assigned the correct sourcetype, the developers have been instructed to include specific HEC headers. However, the Splunk Cloud admin notices all data is landing in the default index for the HEC token. Which TWO of the following could be the cause of this issue? (Select TWO)
Show answer & explanation
Correct answers: B, E
- Question 2Advanced
Manipulating Raw Data · Use transformations with props.conf and transforms.conf to modify raw data
A Splunk Cloud admin needs to mask Personally Identifiable Information (PII) from incoming web server logs. Specifically, the credit card numbers in the format
CCN=1234-5678-9012-3456must be replaced withCCN=XXXX-XXXX-XXXX-XXXXat index time. Which configuration combination inprops.confandtransforms.confon the search head (or relevant parsing tier) will accomplish this?Show answer & explanation
Correct answer: C
This is the correct method for index-time data masking. The
props.confstanza invokes a transformation. Thetransforms.confstanza defines that transformation:REGEXmatches the pattern to be replaced,FORMATdefines the replacement string, andDEST_KEY = _rawspecifies that the transformation should be applied directly to the raw event data before it is written to disk. - Question 3Intermediate
Forwarder Management · Managing forwarders using deployment apps
A Splunk Cloud administrator is using a Deployment Server to manage a fleet of Universal Forwarders. A new server class,
[serverClass:linux_web_servers], has been created to deploy a web log collection app. However, after creating the server class, none of the target Linux servers are downloading the new app. Thewhitelist.0is correctly configured to match the hostnames. What is a common reason for this failure?Show answer & explanation
Correct answer: B
After making changes to
serverclass.confor adding/modifying apps in the deployment-apps directory, the deployment server configuration must be reloaded for the changes to take effect. This can be done via the UI or by running the CLI commandsplunk reload deploy-server. Without this step, the deployment server is unaware of the new server class and will not instruct clients to download the associated apps. - Question 4Beginner
Index Management · Create indexes in cloud
When creating a new index in Splunk Cloud Platform via the UI, what is the purpose of the 'Max Size of Entire Index' setting?
Show answer & explanation
Correct answer: C
The 'Max Size of Entire Index' (internally
maxTotalDataSizeMB) setting determines the maximum total size the index can occupy on disk. When this size limit is reached, Splunk will begin to delete the oldest data (buckets) from the index to make room for new data, regardless of the time-based retention policy ('Retention (days)'). It is a size-based retention control. - Question 5Intermediate
Network and Other Inputs · Create a basic scripted input
A Splunk Cloud admin is setting up a scripted input on a Linux Universal Forwarder. The script,
/opt/splunkforwarder/bin/scripts/get_metrics.sh, runs correctly when executed manually from the command line. Theinputs.confstanza is as follows:[script:///opt/splunkforwarder/bin/scripts/get_metrics.sh] interval = 300 sourcetype = custom_metrics index = metrics disabled = 0After configuration, no data appears in the
metricsindex. What is the most likely cause for this issue?Show answer & explanation
Correct answer: B
For a scripted input to work, the Splunk process (typically running as user 'splunk') must have execute permissions on the script file. Even if the script runs correctly for the admin user ('root' or another user), it will fail to execute by the forwarder if permissions are not correctly set (e.g., via
chmod a+x get_metrics.sh). This is one of the most common issues with scripted inputs. - Question 6Advanced
Getting Data in Cloud · List Splunk forwarder types
A Splunk Cloud admin needs to configure inputs for a new application. The application logs contain sensitive user data. The security team has mandated that this sensitive data must be nullified before it leaves the source machine. Which Splunk forwarder type and configuration file should be used to meet this requirement?
Show answer & explanation
Correct answer: B
A Universal Forwarder sends raw, unmodified data. To perform data manipulation like masking or filtering based on event content (parsing), a Heavy Forwarder is required. A Heavy Forwarder has a full parsing pipeline, allowing it to use
props.confandtransforms.confto modify the_rawevent data before forwarding it to the Splunk Cloud indexers. - Question 7Intermediate
Monitor Inputs · Use optional settings for monitor inputs
What is the primary function of the
crcSaltattribute in a[monitor]stanza withininputs.conf?Show answer & explanation
Correct answer: C
The
crcSaltattribute adds a specified string to the beginning of a file before Splunk computes its checksum (CRC). This is crucial for tracking log files that are rotated or copied. If a log file is copied and truncated, withoutcrcSalt, Splunk might see the first few bytes as identical and mistakenly believe it has already indexed that part of the file. By adding a salt (like the full source path), it ensures each file has a unique checksum, preventing data loss or duplication during log rotation. - Question 8Intermediate
Parsing Phase and Data Preview · Explain how timestamps and time zones are extracted or assigned to events
A Splunk Cloud administrator is investigating why timestamps for a particular sourcetype (
custom_log) are being assigned the current system time instead of being extracted from the event body. The administrator has verified that a timestamp exists in the raw data. Which configuration setting inprops.confis most likely responsible for this behavior?Show answer & explanation
Correct answer: A
The
DATETIME_CONFIG = CURRENTsetting explicitly tells Splunk to stop searching for a timestamp within the event data for the specified sourcetype and to instead use the current system time of the parsing instance as the event's timestamp. This setting overrides all other time extraction parameters likeTIME_PREFIXandTIME_FORMAT. - Question 9Beginner
Installing and Managing Apps · Describe private apps
A Splunk Cloud admin needs to install a private app that is not available on Splunkbase. The app consists of several configuration files and dashboards. What is the standard procedure for installing this private app in a Splunk Cloud Platform environment?
Show answer & explanation
Correct answer: A
For Splunk Cloud Platform, private apps must be vetted by Splunk Support before they can be installed. The standard process is to open a support case and attach the app package. Splunk Support will validate the app against Cloud security and operational requirements (a process similar to AppInspect) and, upon approval, will install it on the customer's behalf.
- Question 10Intermediate
Splunk Configuration Files · Review configuration file precedence
The configuration precedence order in Splunk determines which version of a setting is used when it is defined in multiple locations. For a given app context, which location has the highest precedence?
Show answer & explanation
Correct answer: D
Splunk's configuration precedence is designed so that the most specific settings override more general ones. The highest level of precedence for a setting within an app's context is the app's own
localdirectory. This overrides the app'sdefaultdirectory, any system-level directories, and any settings from other apps.
Ready for the real thing?
The full SPLK-1005 simulator has every exam-style question, timed mode, and instant scoring.