Splunk splk-1001 practice test

Splunk Core Certified User

Last exam update: Dec 23 ,2025
Page 1 out of 17. Viewing questions 1-15 out of 244

Question 1

What is the correct syntax to count the number of events containing a vendor_action field?

  • A. count stats vendor_action
  • B. count stats (vendor_action)
  • C. stats count (vendor_action)
  • D. stats vendor_action (count)
Mark Question:
Answer:

C


Explanation:
The stats command calculates statistics based on fields in the events. The count function counts the
number of events that match the criteria. The syntax is stats count (field_name), where field_name is
the name of the field that contains the value to be counted. In this case, vendor_action is the field
name, so stats count (vendor_action) is the correct syntax. Reference:
Splunk Core User Certification
Exam Study Guide
, page 23.

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 2

By default, which of the following fields would be listed in the fields sidebar under interesting Fields?

  • A. host
  • B. index
  • C. source
  • D. sourcetype
Mark Question:
Answer:

D


Explanation:
The fields sidebar in Splunk shows the default fields and the interesting fields for the events that
match your search. The default fields are host, source, and sourcetype, which are extracted for every
event at index time. The interesting fields are fields that appear in at least 20% of the events in your
search results.
You can also select additional fields to display in the fields sidebar1
.
By default, the index field is not listed in the fields sidebar, because it is not a default field nor an
interesting field. The index field is a metadata field that indicates which index the event belongs to.
Metadata fields are not extracted from the event data, but are added by the indexer as part of the
indexing process.
Metadata fields are not shown in the fields sidebar, but you can use them in your
search queries2
.
Therefore, among the four options, only sourcetype would be listed in the fields sidebar under
interesting fields by default.
Reference
Use fields to search
About default fields

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 3

When looking at a dashboard panel that is based on a report, which of the following is true?

  • A. You can modify the search string in the panel, and you can change and configure the visualization.
  • B. You can modify the search string in the panel, but you cannot change and configure the visualization.
  • C. You cannot modify the search string in the panel, but you can change and configure the visualization.
  • D. You cannot modify the search string in the panel, and you cannot change and configure the visualization.
Mark Question:
Answer:

C


Explanation:
When looking at a dashboard panel that is based on a report, you cannot modify the search string in
the panel, but you can change and configure the visualization. This is because the dashboard panel
inherits the search string from the report, and any changes to the search string will affect the report
as well. However, you can customize the visualization settings for the dashboard panel without
affecting the report. Reference:
Splunk Core User Certification Exam Study Guide
, page 37.

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 4

Which of the following is a best practice when writing a search string?

  • A. Include all formatting commands before any search terms
  • B. Include at least one function as this is a search requirement
  • C. Include the search terms at the beginning of the search string
  • D. Avoid using formatting clauses as they add too much overhead
Mark Question:
Answer:

C


Explanation:
A best practice when writing a search string is to include the search terms at the beginning of the
search string. This helps Splunk narrow down the events that match your search criteria and improve
the search performance. Formatting commands and functions can be added later in the search
pipeline to manipulate and display the results. Reference:
Splunk Core User Certification Exam Study
Guide
, page 13.

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 5

What type of search can be saved as a report?

  • A. Any search can be saved as a report
  • B. Only searches that generate visualizations
  • C. Only searches containing a transforming command
  • D. Only searches that generate statistics or visualizations
Mark Question:
Answer:

D


Explanation:
Only searches that generate statistics or visualizations can be saved as a report. These are searches
that contain a transforming command, such as stats, chart, timechart, top, rare, etc. Transforming
commands create a data table from the events and enable various types of visualizations. Searches
that do not contain a transforming command can only be saved as an alert or a dashboard panel.
Reference:
Splunk Core User Certification Exam Study Guide
, page 35.

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 6

What can be included in the All Fields option in the sidebar?

  • A. Dashboards
  • B. Metadata only
  • C. Non-interesting fields
  • D. Field descriptions
Mark Question:
Answer:

C


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 7

What syntax is used to link key/value pairs in search strings?

  • A. action+purchase
  • B. action=purchase
  • C. action | purchase
  • D. action equal purchase
Mark Question:
Answer:

B


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 8

When viewing the results of a search, what is an Interesting Field?

  • A. A field that appears in any event
  • B. A field that appears in every event
  • C. A field that appears in the top 10 events
  • D. A field that appears in at least 20% of the events
Mark Question:
Answer:

D


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 9

What syntax is used to link key/value pairs in search strings?

  • A. Parentheses
  • B. @ or # symbols
  • C. Quotation marks
  • D. Relational operators such as =, <, or >
Mark Question:
Answer:

D


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 10

When a Splunk search generates calculated data that appears in the Statistics tab. in what formats
can the results be exported?

  • A. CSV, JSON, PDF
  • B. CSV, XML JSON
  • C. Raw Events, XML, JSON
  • D. Raw Events, CSV, XML, JSON
Mark Question:
Answer:

D


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 11

Which of the following are functions of the stats command?

  • A. count, sum, add
  • B. count, sum, less
  • C. sum, avg, values
  • D. sum, values, table
Mark Question:
Answer:

C


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 12

In a deployment with multiple indexes, what will happen when a search is run and an index is not
specified in the search string?

  • A. No events will be returned.
  • B. Splunk will prompt you to specify an index.
  • C. All non-indexed events to which the user has access will be returned.
  • D. Events from every index searched by default to which the user has access will be returned.
Mark Question:
Answer:

D


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 13

Which search matches the events containing the terms "error" and "fail"?

  • A. index=security Error Fail
  • B. index=security error OR fail
  • C. index=security “error failure”
  • D. index=security NOT error NOT fail
Mark Question:
Answer:

A


Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/SearchReference/Search

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 14

Which of the following is an option after clicking an item in search results?

  • A. Saving the item to a report
  • B. Adding the item to the search.
  • C. Adding the item to a dashboard
  • D. Saving the search to a JSON file.
Mark Question:
Answer:

A


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 15

When placed early in a search, which command is most effective at reducing search execution time?

  • A. dedup
  • B. rename
  • C. sort -
  • D. fields +
Mark Question:
Answer:

A


User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000
To page 2