Splunk SPLK-1002 Practice Exams
Last updated on Oct 06,2026- Exam Code: SPLK-1002
- Exam Name: Splunk Core Certified Power User
- Certification Provider: Splunk
- Latest update: Oct 06,2026
Which of the following can be saved as an event type?
- A . index=server sourcetype=BETA_718 code=UB9 | stats count by code
- B . index=server_494 sourcetype=BETA_718 code=889
- C . index=server_494 sourcetype=BETA_718 code=839 stats where code > 203
- D . index=server_494 sourcetype=BETA_718 code=839 | inputlookup append=t servercode.csv
What is a benefit of installing the Splunk Common Information Model (CIM) add-on?
- A . It permits users to create workflow actions to align with industry standards.
- B . It provides users with a standardized set of field names and tags to normalize data.
- C . It allows users to create 3-D models of their data and export these visualizations.
- D . It enables users to itemize their events based on the results of the Search Job Inspector.
This is what Splunk uses to categorize the data that is being indexed.
- A . Host
- B . Sourcetype
- C . Index
- D . Source
Which of the following statements describes the command below (select all that apply)
Sourcetype=access_combined | transaction JSESSIONID
- A . An additional filed named maxspan is created.
- B . An additional field named duration is created.
- C . An additional field named eventcount is created.
- D . Events with the same JSESSIONID will be grouped together into a single event.
The eval command allows you to do which of the following? (Choose all that apply.)
- A . Format values
- B . Convert values
- C . Perform calculations
- D . Use conditional statements
This is what Splunk uses to categorize the data that is being indexed.
- A . sourcetype
- B . index
- C . source
- D . host
Data model are composed of one or more of which of the following datasets? (select all that apply.)
- A . Events datasets
- B . Search datasets
- C . Transaction datasets
- D . Any child of event, transaction, and search datasets
Which one of the following statements about the search command is true?
- A . It does not allow the use of wildcards.
- B . It treats field values in a case-sensitive manner.
- C . It can only be used at the beginning of the search pipeline.
- D . It behaves exactly like search strings before the first pipe.
What does the Splunk Common Information Model (CIM) add-on include? (select all that apply)
- A . Custom visualizations
- B . Pre-configured data models
- C . Fields and event category tags
- D . Automatic data model acceleration
Which delimiters can the Field Extractor (FX) detect? (select all that apply)
- A . Tabs
- B . Pipes
- C . Spaces
- D . Commas