Splunk SPLK-1002 Practice Exams
Last updated on Oct 06,2026- Exam Code: SPLK-1002
- Exam Name: Splunk Core Certified Power User
- Certification Provider: Splunk
- Latest update: Oct 06,2026
Question #51
Which of the following expressions could be used to create a calculated field called gigabytes?
- A . eval sc_bytes(1024/1024)
- B . | eval negabytes=sc_bytes(1024/1024)
- C . megabytes=sc_bytes(1024/1024)
- D . sc_bytas(1024/1024)
Question #52
When using | timechart by host, which field is represented in the x-axis?
- A . date
- B . host
- C . time
- D . _time
Question #53
Splunk alerts can be based on search that run______. (Select all that apply.)
- A . in real-time
- B . on a regular schedule
- C . and have no matching events
Question #54
A calculated field maybe based on which of the following?
- A . Lookup tables
- B . Extracted fields
- C . Regular expressions
- D . Fields generated within a search string
Question #55
Calculated fields can be based on which of the following?
- A . Tags
- B . Extracted fields
- C . Output fields for a lookup
- D . Fields generated from a search string
Question #56
Which of the following statements describes an event type?
- A . A log level measurement: info, warn, error.
- B . A knowledge object that is applied before fields are extracted.
- C . A field for categorizing events based on a search string.
- D . Either a log, a metric, or a trace.
Question #57
These users can create global knowledge objects. (Select all that apply.)
- A . users
- B . power users
- C . administrators
Question #58
When using transaction, what is the default maximum span between events?
- A . Unlimited
- B . 1h
- C . 1m
- D . 1d
Question #59
A POST workflow action will pass which types of arguments to an external website?
- A . Clear text only.
- B . A mix of clear text strings and variables.
- C . It can only send raw event data.
- D . Variables only.
Question #60
Which of the following can be saved as an event type?
- A . index=server_48 sourcetype=BETA_881 code=220
- B . index=server_48 sourcetype=BETA_881 code=220 | stats count by code
- C . index=server_48 sourcetype=BETA_881 code=220 | inputlookup append=t servercode.csv
- D . index=server_48 sourcetype=BETA_881 code=220 | stats where code > 220