SPLK-1005 Sample Questions

SPLK-1005 Sample Questions & Answers

Getting data into the cloud service ties with configuring monitor inputs for the heaviest weight, next to network and scripted inputs, parsing and data preview, manipulating raw data, cloud topology basics, forwarder management, and working with cloud support.

Launch the full SPLK-1005 simulator →

Showing 10 of 20 free samples.

  1. Question 1IntermediateSelect 2

    Network and Other Inputs · Use the HTTP Event Collector (HEC) to get data into Splunk

    An e-commerce company uses the Splunk HTTP Event Collector (HEC) to ingest transaction data from a microservice. To ensure data is routed to the correct index and assigned the correct sourcetype, the developers have been instructed to include specific HEC headers. However, the Splunk Cloud admin notices all data is landing in the default index for the HEC token. Which TWO of the following could be the cause of this issue? (Select TWO)

    Show answer & explanation

    Correct answers: B, E

  2. Question 2Advanced

    Manipulating Raw Data · Use transformations with props.conf and transforms.conf to modify raw data

    A Splunk Cloud admin needs to mask Personally Identifiable Information (PII) from incoming web server logs. Specifically, the credit card numbers in the format CCN=1234-5678-9012-3456 must be replaced with CCN=XXXX-XXXX-XXXX-XXXX at index time. Which configuration combination in props.conf and transforms.conf on the search head (or relevant parsing tier) will accomplish this?

    Show answer & explanation

    Correct answer: C

    This is the correct method for index-time data masking. The props.conf stanza invokes a transformation. The transforms.conf stanza defines that transformation: REGEX matches the pattern to be replaced, FORMAT defines the replacement string, and DEST_KEY = _raw specifies that the transformation should be applied directly to the raw event data before it is written to disk.

  3. Question 3Intermediate

    Forwarder Management · Managing forwarders using deployment apps

    A Splunk Cloud administrator is using a Deployment Server to manage a fleet of Universal Forwarders. A new server class, [serverClass:linux_web_servers], has been created to deploy a web log collection app. However, after creating the server class, none of the target Linux servers are downloading the new app. The whitelist.0 is correctly configured to match the hostnames. What is a common reason for this failure?

    Show answer & explanation

    Correct answer: B

    After making changes to serverclass.conf or adding/modifying apps in the deployment-apps directory, the deployment server configuration must be reloaded for the changes to take effect. This can be done via the UI or by running the CLI command splunk reload deploy-server. Without this step, the deployment server is unaware of the new server class and will not instruct clients to download the associated apps.

  4. Question 4Beginner

    Index Management · Create indexes in cloud

    When creating a new index in Splunk Cloud Platform via the UI, what is the purpose of the 'Max Size of Entire Index' setting?

    Show answer & explanation

    Correct answer: C

    The 'Max Size of Entire Index' (internally maxTotalDataSizeMB) setting determines the maximum total size the index can occupy on disk. When this size limit is reached, Splunk will begin to delete the oldest data (buckets) from the index to make room for new data, regardless of the time-based retention policy ('Retention (days)'). It is a size-based retention control.

  5. Question 5Intermediate

    Network and Other Inputs · Create a basic scripted input

    A Splunk Cloud admin is setting up a scripted input on a Linux Universal Forwarder. The script, /opt/splunkforwarder/bin/scripts/get_metrics.sh, runs correctly when executed manually from the command line. The inputs.conf stanza is as follows:

    [script:///opt/splunkforwarder/bin/scripts/get_metrics.sh]
    interval = 300
    sourcetype = custom_metrics
    index = metrics
    disabled = 0
    

    After configuration, no data appears in the metrics index. What is the most likely cause for this issue?

    Show answer & explanation

    Correct answer: B

    For a scripted input to work, the Splunk process (typically running as user 'splunk') must have execute permissions on the script file. Even if the script runs correctly for the admin user ('root' or another user), it will fail to execute by the forwarder if permissions are not correctly set (e.g., via chmod a+x get_metrics.sh). This is one of the most common issues with scripted inputs.

  6. Question 6Advanced

    Getting Data in Cloud · List Splunk forwarder types

    A Splunk Cloud admin needs to configure inputs for a new application. The application logs contain sensitive user data. The security team has mandated that this sensitive data must be nullified before it leaves the source machine. Which Splunk forwarder type and configuration file should be used to meet this requirement?

    Show answer & explanation

    Correct answer: B

    A Universal Forwarder sends raw, unmodified data. To perform data manipulation like masking or filtering based on event content (parsing), a Heavy Forwarder is required. A Heavy Forwarder has a full parsing pipeline, allowing it to use props.conf and transforms.conf to modify the _raw event data before forwarding it to the Splunk Cloud indexers.

  7. Question 7Intermediate

    Monitor Inputs · Use optional settings for monitor inputs

    What is the primary function of the crcSalt attribute in a [monitor] stanza within inputs.conf?

    Show answer & explanation

    Correct answer: C

    The crcSalt attribute adds a specified string to the beginning of a file before Splunk computes its checksum (CRC). This is crucial for tracking log files that are rotated or copied. If a log file is copied and truncated, without crcSalt, Splunk might see the first few bytes as identical and mistakenly believe it has already indexed that part of the file. By adding a salt (like the full source path), it ensures each file has a unique checksum, preventing data loss or duplication during log rotation.

  8. Question 8Intermediate

    Parsing Phase and Data Preview · Explain how timestamps and time zones are extracted or assigned to events

    A Splunk Cloud administrator is investigating why timestamps for a particular sourcetype (custom_log) are being assigned the current system time instead of being extracted from the event body. The administrator has verified that a timestamp exists in the raw data. Which configuration setting in props.conf is most likely responsible for this behavior?

    Show answer & explanation

    Correct answer: A

    The DATETIME_CONFIG = CURRENT setting explicitly tells Splunk to stop searching for a timestamp within the event data for the specified sourcetype and to instead use the current system time of the parsing instance as the event's timestamp. This setting overrides all other time extraction parameters like TIME_PREFIX and TIME_FORMAT.

  9. Question 9Beginner

    Installing and Managing Apps · Describe private apps

    A Splunk Cloud admin needs to install a private app that is not available on Splunkbase. The app consists of several configuration files and dashboards. What is the standard procedure for installing this private app in a Splunk Cloud Platform environment?

    Show answer & explanation

    Correct answer: A

    For Splunk Cloud Platform, private apps must be vetted by Splunk Support before they can be installed. The standard process is to open a support case and attach the app package. Splunk Support will validate the app against Cloud security and operational requirements (a process similar to AppInspect) and, upon approval, will install it on the customer's behalf.

  10. Question 10Intermediate

    Splunk Configuration Files · Review configuration file precedence

    The configuration precedence order in Splunk determines which version of a setting is used when it is defined in multiple locations. For a given app context, which location has the highest precedence?

    Show answer & explanation

    Correct answer: D

    Splunk's configuration precedence is designed so that the most specific settings override more general ones. The highest level of precedence for a setting within an app's context is the app's own local directory. This overrides the app's default directory, any system-level directories, and any settings from other apps.

Ready for the real thing?

The full SPLK-1005 simulator has every exam-style question, timed mode, and instant scoring.