Splunk SPLK-1002 Practice Exams
Last updated on Oct 06,2026- Exam Code: SPLK-1002
- Exam Name: Splunk Core Certified Power User
- Certification Provider: Splunk
- Latest update: Oct 06,2026
In which of the following scenarios is an event type more effective than a saved search?
- A . When a search should always include the same time range.
- B . When a search needs to be added to other users’ dashboards.
- C . When the search string needs to be used in future searches.
- D . When formatting needs to be included with the search string.
The timechart command buckets data in time intervals depending on:
- A . the number of events returned
- B . the selected time range
- C . the type of visualization selected
What is the correct syntax to find events associated with a tag?
- A . tag:<field>=<value>
- B . tags=<value>
- C . tags:<field>=<value>
- D . tag=<value>
Which field extraction method should be selected for comma-separated data?
- A . Regular expression
- B . Delimiters
- C . eval expression
- D . table extraction
What other syntax will produce exactly the same results as | chart count over vendor_action by user?
- A . | chart count by vendor_action, user
- B . | chart count over vendor_action, user
- C . | chart count by vendor_action over user
- D . | chart count over user by vendor_action
How are event types different from saved reports?
- A . Event types cannot be used to organize data into categories.
- B . Event types include formatting of the search results.
- C . Event types can be shared with Splunk users and added to dashboards.
- D . Event types do not include a time range.
Data model fields can be added using the Auto-Extracted method.
Which of the following statements describe Auto-Extracted fields? (select all that apply)
- A . Auto-Extracted fields can be hidden in Pivot.
- B . Auto-Extracted fields can have their data type changed.
- C . Auto-Extracted fields can be given a friendly name for use in Pivot.
- D . Auto-Extracted fields can be added if they already exist in the dataset with constraints.
Which of the following data models are included in the Splunk Common Information Model (CIM)
add-on? (select all that apply)
- A . User permissions
- B . Alerts
- C . Databases
- D . Email
Which of the following describes the I transaction command?
- A . It is an SPL command that groups at least two events together based on shared values in selected fields.
- B . It allows an exchange of data from one Splunk index to another Splunk index.
- C . It is an SPL command that groups events together with shared values in selected fields.
- D . It allows an exchange of data from one Splunk system to another Splunk system.