Splunk SPLK-1004 Practice Exams
Last updated on Oct 06,2026- Exam Code: SPLK-1004
- Exam Name: Splunk Core Certified Advanced Power User Exam
- Certification Provider: Splunk
- Latest update: Oct 06,2026
What XML element is used to pass multiple fields into another dashboard using a dynamic drilldown?
- A . <drilldown field_"sources_Field_name">
- B . <condition field_"sources_Field_name">
- C . <pas_token field_"sources_field_name">
- D . <link field_"sources_field_name">
D
Explanation:
In Splunk Simple XML for dashboards, dynamic drilldowns are configured within the <drilldown> element, not <link>, <condition>, or <pass_token>. To pass multiple fields to another dashboard, you would use a combination of <set> tokens within the <drilldown> element. Each <set> token specifies a field or value to be passed.
The correct configuration might look something like this within the <drilldown> element:
<drilldown>
<set token="token1">$row.field1$</set>
<set token="token2">$row.field2$</set>
<link target="_blank">/app/search/new_dashboard</link> </drilldown>
In this configuration, $row.field1$ and $row.field2$ are placeholders for the field values from the clicked event, which are assigned to tokens token1 and token2. These tokens can then be used in the target dashboard to receive the values. The <link> element specifies the target dashboard. Note that
![]()
the exact syntax can vary based on the specific requirements of the drilldown and the dashboard configuration.
What is returned when Splunk finds fewer than the minimum matches for each lookup value?
- A . The default value NULL until the minimum match threshold is reached.
- B . The default match value until the minimum match threshold Is reached.
- C . The first match unless the time_field attribute is specified.
- D . Only the first match.
A
Explanation:
When Splunk’s lookup feature finds fewer than the minimum matches specified for each lookup value, it returns the default value NULL for those unmatched entries until the minimum match threshold is reached (Option A). This behavior ensures that lookups return consistent and expected results, even when the available data does not meet the specified criteria for a minimum number of matches.
What is the correct hierarchy of XML elements in a dashboard panel?
- A . <panel><dashboard><row>
- B . <dashboard><row><panel>
- C . <dashboard><panel><row>
- D . <panel><row><dashboard>
B
Explanation:
In a Splunk dashboard, the correct hierarchy of XML elements for a dashboard panel is <dashboard><row><panel> (Option B). A Splunk dashboard is defined within the <dashboard> element. Within this, <row> elements are used to organize the layout into rows, and each <panel> element within a row defines an individual panel that can contain visualizations, searches, or other content. This hierarchical structure allows for organized and customizable layouts of dashboard elements, facilitating clear presentation of data and analyses. The other options provided do not represent the correct hierarchical order for defining dashboard panels in Splunk’s XML dashboard syntax.
How can the inspect button be disabled on a dashboard panel?
- A . Set inspect.link.disabled to 1
- B . Set link.inspect .visible to 0
- C . Set link.inspectSearch.visible too
- D . Set link.search.disabled to 1
If a search contains a subsearch, what is the order of execution?
- A . The order of execution depends on whether either search uses a stats command.
- B . The inner search executes first.
- C . The otter search executes first.
- D . The two searches are executed in parallel.
B
Explanation:
In a Splunk search containing a subsearch, the inner subsearch executes first (Option B). The result of the subsearch is then passed to the outer search. This is because the outer search often depends on the results of the inner subsearch to complete its execution. For example, a subsearch might be used to identify a list of relevant terms or values which are then used by the outer search to filter or manipulate the main dataset.
When using a nested search macro, how can an argument value be passed to the inner macro?
- A . The argument value may be passed to the outer macro.
- B . An argument cannot be used with an inner nested macro.
- C . An argument cannot be used with an outer nested macro.

- D . The argument value must be specified in the outer macro.
A
Explanation:
When using a nested search macro in Splunk, an argument value can be passed to the inner macro by specifying the argument in the outer macro’s invocation (Option A). This allows the outer macro to accept arguments from the user or another search command and then pass those arguments into the inner macro, enabling dynamic and flexible macro compositions that can adapt based on input parameters.
How is a cascading input used?
- A . As part of a dashboard, but not in a form.
- B . Without notation in the underlying. XML.
- C . As a way to filter other input selections.
- D . As a default way to delete a user role.
C
Explanation:
A cascading input is used as a way to filter other input selections within a dashboard or form (Option C). It enables a dynamic user interface where the selection made in one input (e.g., a dropdown menu) determines the available options in another input. This setup allows for more intuitive and relevant user interactions, as each choice narrows down the subsequent options to ensure they are contextually appropriate.
Which of the following is an event handler action?
- A . Run an eval statement based on a user clicking a value on a form.
- B . Set a token to select a value from the time range picker.
- C . Pass a token from a drilldown to modify index settings.
- D . Cancel all jobs based on the number of search job results captured.
A
Explanation:
An event handler action in Splunk is an action that is triggered based on user interaction with dashboard elements. Running an eval statement based on a user clicking a value on a form (Option
A) is an example of an event handler action. This capability allows dashboards to be interactive and dynamic, responding to user inputs or actions to modify displayed data, visuals, or other elements in real-time.
What does the query | makeresults generate?
- A . A timestamp
- B . A results field
- C . An error message
- D . The results of the previously run search.
Which search generates a field with a value of "hello"?
- A . | Makeresults field-‘’hello’’
- B . | Makeresults | fields‘’hello’’
- C . | Makeresults | eval field-‘’hello’’
- D . | Makeresults | eval field =make{’’hello’’}
C
Explanation:
To generate a field with a value of "hello" using the makeresults command in Splunk, the correct syntax is | makeresults | eval field="hello" (Option C). The makeresults command creates a single event, and the eval command is used to add a new field (named "field" in this case) with the specified value ("hello"). This is a common method for creating sample data or for demonstration purposes within Splunk searches.