Splunk SPLK-1002 Practice Exams
Last updated on Oct 06,2026- Exam Code: SPLK-1002
- Exam Name: Splunk Core Certified Power User
- Certification Provider: Splunk
- Latest update: Oct 06,2026
Question #91
In what order arc the following knowledge objects/configurations applied?
- A . Field Aliases, Field Extractions, Lookups
- B . Field Extractions, Field Aliases, Lookups
- C . Field Extractions, Lookups, Field Aliases
- D . Lookups, Field Aliases, Field Extractions
Question #92
How is a variable for a macro defined?
- A . Place the variable name inside of curly braces: {variable name}.
- B . Place the variable name inside of asterisks: variable name.
- C . Place the variable name inside of dollar signs: $variable name$.
- D . Place the variable name inside of percentage signs: %variable name%.
Question #93
Question #94
The eval command ‘if’ function requires the following three arguments (in order):
- A . Boolean expression, result if true, result if false
- B . Result if true, result if false, boolean expression
- C . Result if false, result if true, boolean expression
- D . Boolean expression, result if false, result if true
Question #95
What is required for a macro to accept three arguments?
- A . The macro’s name ends with (3).
- B . The macro’s name starts with (3).
- C . The macro’s argument count setting is 3 or more.
- D . Nothing, all macros can accept any number of arguments.
Question #96
How can an existing accelerated data model be edited?
- A . An accelerated data model can be edited once its .tsidx file has expired.
- B . An accelerated data model can be edited from the Pivot tool.
- C . The data model must be de-accelerated before edits can be made to its structure.
- D . It cannot be edited. A new data model would need to be created.
Question #97
Which statement is true?
- A . Pivot is used for creating datasets.
- B . Data models are randomly structured datasets.
- C . Pivot is used for creating reports and dashboards.
- D . In most cases, each Splunk user will create their own data model.
Question #98
What approach is recommended when using the Splunk Common Information Model (CIM) add-on to normalize data?
- A . Consult the CIM data model reference tables.
- B . Run a search using the authentication command.
- C . Consult the CIM event type reference tables.
- D . Run a search using the correlation command.
Question #99
When does the CIM add-on apply preconfigured data models to the data?
- A . Search time
- B . Index time
- C . On a cron schedule
- D . At midnight
Question #100
Selected fields are displayed ______each event in the search results.
- A . below
- B . interesting fields
- C . other fields
- D . above