SPLK-4001 Sample Questions & Answers
Ten equally weighted areas cover charts and timecharts, filtering with eval, search and where, tying events into transactions, extracting and aliasing fields, tagging events, macros, workflow actions, data models, and the CIM add-on.
Launch the full SPLK-4001 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Using Transforming Commands for Visualizations · Combining top and eventstats for percentage calculation
A Power User is analyzing web server logs and needs to display the top 5 product categories by sales count, but also wants to include a column showing the percentage of total sales for each category. Which search query accomplishes this?
Show answer & explanation
Correct answer: C
This is a multi-step process. First,
stats count by categoryIdcalculates the sales for each category. Then,eventstats sum(count) as totalcalculates the grand total of all sales and adds it as a new fieldtotalto every row without collapsing the results.evalthen calculates the percentage. Finally, the results are sorted and limited to the top 5. Thetopcommand provides apercentfield, but it's based on the percentage of events processed, not the percentage of the total count of the grouped field, which is whateventstatscorrectly calculates. - Question 2Beginner
Creating and Using Workflow Actions · GET workflow action with field substitution
A security analyst needs to create a workflow action that, when triggered from an event containing a suspicious IP address (field
suspicious_ip), opens a new browser tab to an external threat intelligence service. The URL should behttps://threat.local/lookup?ip=VALUE. Which workflow action configuration is correct?Show answer & explanation
Correct answer: C
A GET workflow action is used to open a URL. The
$field_name$syntax is used within the URI to substitute the value of a field from the triggering event. In this case,$suspicious_ip$will be replaced with the actual IP address from the event, constructing the correct URL for the lookup. - Question 3Intermediate
Creating and Managing Fields · JSON field extraction and aliasing
A developer is working with JSON logs that contain a nested object for user details. An example event is:
{"event_id": 123, "user": {"id": "user_a", "region": "us-east-1"}, "status": "success"}. The goal is to extract theidandregionas top-level fields nameduser_idanduser_region. How can this be accomplished efficiently for all future searches on this sourcetype?Show answer & explanation
Correct answer: B
Splunk automatically parses well-formed JSON at search time, creating fields for nested objects using dot notation (e.g.,
user.id). To make these fields available asuser_idanduser_regionfor all future searches on this sourcetype, the most efficient and persistent method is to create field aliases. This avoids runningspathorrexcommands in every search. - Question 4Intermediate
Filtering and Formatting Results · Using fillnull with timechart
A Power User is creating a report that shows the daily count of different HTTP status codes. However, on days where a specific status code (e.g., 404) did not occur, it is missing from the
timechartoutput. What command should be used to ensure all status codes appear in the legend and have a value of 0 for days they did not occur?Show answer & explanation
Correct answer: D
The
timechartcommand produces a table where rows are timestamps and columns are the split-by field values. If a value does not exist for a given time bucket, a null value is produced. Piping the output oftimecharttofillnull value=0will replace all of those null values with 0, ensuring every status code has a data point for every time interval. - Question 5Beginner
Creating Tags and Event Types · Benefits of event types
A team frequently runs a search to find successful logins followed by a failed action from the same user within 5 minutes. To simplify this, an event type named
login_then_failis created. Which statement accurately describes the primary benefit of using this event type?Show answer & explanation
Correct answer: B
Event types are essentially saved searches that act as a classification for events. Their main purpose is to categorize data based on patterns, making it easier to search for complex events without retyping the entire search string. You can simply search for
eventtype=login_then_fail. Event types do not inherently accelerate searches; that is a function of data model acceleration. - Question 6Intermediate
Correlating Events · Using transaction for long-running processes
A retail company wants to track the entire lifecycle of a customer's order, from
order_placedtopayment_processedtoorder_shipped. Each event has a uniqueorder_id. Some orders can take days to ship. The analyst must group all events for eachorder_idinto a single result and calculate the total time from placement to shipment.Which command is best suited for this requirement?
Show answer & explanation
Correct answer: B
The
transactioncommand is designed specifically for grouping related events, even if they are far apart in time. By specifyingtransaction order_id, it will group all events with the same order ID. Themaxspan=5d(or another appropriate duration) is crucial to ensure that long-running transactions that span multiple days are not prematurely closed. The command automatically creates adurationfield representing the time between the first and last event in the transaction. - Question 7Beginner
Filtering and Formatting Results · Using the eval if() function
A Power User is analyzing application performance data which includes a
response_time_msfield. The user wants to create a new field calledsla_statuswhich should be 'Met' if the response time is less than or equal to 500ms, and 'Breached' otherwise. Whichevalexpression correctly creates this field?Show answer & explanation
Correct answer: C
The
if(X, Y, Z)function within theevalcommand is the most direct way to handle binary conditional logic. It evaluates the conditionX(response_time_ms <= 500). If true, it returnsY("Met"). If false, it returnsZ("Breached"). Thecasefunction also works but is more verbose for a simple if/else condition. - Question 8Intermediate
Creating Tags and Event Types · Knowledge object permissions
A Power User has created a series of knowledge objects (field extractions, event types, and tags) for a new
secure_appsourcetype. By default, these knowledge objects are private to the user. What is the correct procedure to make them available to all users within the Search & Reporting app?Show answer & explanation
Correct answer: C
Splunk's knowledge object permissions model allows for sharing at two main levels: private (user only) and app context. To make objects available to others within the same app (like Search & Reporting), you must change the sharing from 'Private' to 'This app only (search)'. Then, you must configure the permissions to grant 'Read' access to the desired roles, such as 'everyone' or specific user roles.
- Question 9IntermediateSelect 2
Using the Common Information Model (CIM) Add-On · Core concepts of CIM
Which of the following statements about the Splunk Common Information Model (CIM) are true? (Select TWO)
graph TD subgraph RawData [Vendor Logs] A[Cisco ASA] B[Palo Alto FW] C[Windows Security] end subgraph Normalization [CIM Add-on] D{Tags, Aliases, Event Types} end subgraph DataModels [CIM Data Models] E[Network_Traffic] F[Authentication] end subgraph UseCases [Splunk Apps] G[Splunk Enterprise Security] H[Custom Dashboards] end RawData --> Normalization Normalization --> DataModels DataModels --> UseCasesShow answer & explanation
Correct answers: B, C
- Question 10Beginner
Creating and Managing Fields · Regular expression field extraction
A Power User needs to extract a user ID from logs where the format is
user: [some_user_id]. The user ID can contain alphanumeric characters and underscores. Which regular expression, used with the Field Extractor, would correctly extractsome_user_idinto a field nameduser?Show answer & explanation
Correct answer: B
This regex correctly identifies the literal string
user: [followed by a named capture group(?P ...)for the fielduser. The\w+pattern matches one or more 'word' characters, which includes alphanumeric characters (a-z, A-Z, 0-9) and the underscore. The.*pattern is too greedy and could capture more than intended if other brackets exist on the line.
Ready for the real thing?
The full SPLK-4001 simulator has every exam-style question, timed mode, and instant scoring.