SPLUNK · SPLK-1001

Splunk SPLK-1001 Exam Practice Questions

212 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 212 questions in this pack

Question 1

Which search string only returns events from hostWWW3?

  1. host=*
  2. host=WWW3
  3. host=WWW*
  4. Host=WWW3
Show answer and explanation

Correct answer: B. host=WWW3

The search string host=WWW3 returns only events where the host field exactly equals WWW3. Option A uses a wildcard that matches any host value, option C uses a wildcard that matches any host starting with WWW, and option D fails because field names are case-sensitive in Splunk (should be lowercase 'host', not 'Host').

Why the other options are wrong

  • A. The wildcard * matches any host value, not just WWW3
  • C. The wildcard * matches any host starting with WWW, including WWW1, WWW2, etc.
  • D. Field names in Splunk are case-sensitive; 'Host' with a capital H will not match the 'host' field

Question 2

By default, how long does Splunk retain a search job?

  1. 10 Minutes
  2. 15 Minutes
  3. 1 Day
  4. 7 Days
Show answer and explanation

Correct answer: A. 10 Minutes

By default, Splunk retains search jobs for 10 minutes. After this time, the job is cleaned up unless it has been saved or explicitly kept. This default setting balances server resource management with reasonable access to recent search results.

Why the other options are wrong

  • B. 15 minutes is longer than the actual default retention period
  • C. 1 day is much longer than the default retention period
  • D. 7 days is much longer than the default retention period

Question 3

What must be done before an automatic lookup can be created? (Choose all that apply.)

  1. The lookup command must be used.
  2. The lookup definition must be created.
  3. The lookup file must be uploaded to Splunk.
  4. The lookup file must be verified using the inputlookup command.
Show answer and explanation

Correct answer: B, C

B. The lookup definition must be created. C. The lookup file must be uploaded to Splunk. An automatic lookup needs two things first: the lookup file and the lookup definition. Upload the CSV, then create a definition that points to it and names its fields. Only then can the automatic lookup apply it to matching events at search time.

Why the other options are wrong

  • A. The lookup command runs manual lookups in a search; automatic lookups need no command.
  • D. inputlookup only previews file contents, never a prerequisite for an automatic lookup.

See all 10 free questions Get the full pack, US$39

212 practice questions for Splunk Core Certified User (SPLK-1001), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 212 questions across all eight SPLK-1001 exam topics
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A failed SPLK-1001 attempt costs US$130, plus the time it takes to prepare again. This pack is US$39, paid once, and refunded if you fail.

Try 10 questions free before you buy.

Last updated September 2026 · 212 questions

What makes the SPLK-1001 hard

SPLK-1001 is where most Splunk careers begin. It proves you can navigate the platform, build searches, work with fields and lookups, and create basic reports and dashboards. The exam tests breadth across the whole platform rather than depth in any one area, and passing it gives you a verified foundation for the exams that follow.

The pace is what catches people out: 60 questions in 60 minutes, one minute per question on average, so there is no time to sit and puzzle over an unfamiliar question style. Working through this pack beforehand means the format is already familiar when the clock starts.

About the exam

The Splunk Core Certified User is the entry point to the Splunk certification path. It validates foundational knowledge of the Splunk platform: searching, using fields, creating alerts, lookups, basic reports and dashboards. There are no prerequisites and no prior Splunk experience is required.

Exam domains

  • Splunk components and navigation
  • Basic searching and search language
  • Using fields in searches
  • Best practices for searching
  • Transforming commands and visualizations
  • Creating reports and dashboards
  • Lookups
  • Scheduled reports and alerts

60 questions, 60 minutes, taken at a Pearson VUE test centre or online proctored, no prerequisites, US$130 per attempt.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the Splunk SPLK-1001 pack?

212 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.