Practice Exam 1
5 of this form’s 60 questions, drawn from across its domains, free. The explanation on every one of them is free too, at every tier, and always will be.
Question 1 of 5
2-4Basic SearchingAn engineer is told to make a slow search cheaper without changing what it reports. Where in the search should the filtering go?
Question 2 of 5
3-3Using Fields in SearchesAn analyst sees the number 5 beside the action field in the sidebar. What does Splunk say that number counts?
Question 3 of 5
4-2Search Language FundamentalsA user is learning how to chain SPL commands together. Which character does Splunk use to link a transforming command to the search before it?
Question 4 of 5
5-2Using Basic Transforming CommandsAn analyst gives the rare command two field names rather than one. What does Splunk say it finds?
Question 5 of 5
6-1Creating Reports and DashboardsA user asks how a report comes into existence in Splunk. What does Splunk say creates one?
0 of 60 completed
The other 55 questions are the rest of this form: same 60 minute clock, same 750 cut score, and the same explanation on every question, which is never behind the wall. Practice Exam 1 of 2 on Core Certified User.
What this exam covers
- Splunk Basics3 questions / 5% of the exam
- Basic Searching13 questions / 22% of the exam
- Using Fields in Searches12 questions / 20% of the exam
- Search Language Fundamentals9 questions / 15% of the exam
- Using Basic Transforming Commands9 questions / 15% of the exam
- Creating Reports and Dashboards7 questions / 12% of the exam
- Creating and Using Lookups4 questions / 6% of the exam
- Creating Scheduled Reports and Alerts3 questions / 5% of the exam
Checking what you already have access to.
Every question is original, written from the published objectives. We never reproduce, paraphrase, or imitate real exam content, and neither should anything else you study from.