SPLUNK · SPLK-1003

Splunk SPLK-1003 Exam Practice Questions

209 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 209 questions in this pack

Question 1

Which setting in indexes.conf allows data retention to be controlled by time?

  1. maxDaysToKeep
  2. moveToFrozenAfter
  3. maxDataRetentionTime
  4. frozenTimePeriodInSecs
Show answer and explanation

Correct answer: D. frozenTimePeriodInSecs

The frozenTimePeriodInSecs setting in indexes.conf controls data retention by specifying the time period (in seconds) after which buckets are moved to frozen. This is the primary time-based retention control in Splunk.

Why the other options are wrong

  • A. maxDaysToKeep is not a valid indexes.conf setting for retention control.
  • B. moveToFrozenAfter is not a valid indexes.conf setting; it does not exist in Splunk.
  • C. maxDataRetentionTime is not the correct setting name used in indexes.conf.

Question 2

The universal forwarder has which capabilities when sending data? (Choose all that apply.)

  1. Sending alerts
  2. Compressing data
  3. Obfuscating/hiding data
  4. Indexer acknowledgement
Show answer and explanation

Correct answer: B, D

B. Compressing data D. Indexer acknowledgement The universal forwarder can compress data to reduce bandwidth usage and provide indexer acknowledgement to ensure reliable delivery. These are core data forwarding capabilities. Alerts are processed at the search head level, and data obfuscation is not a native forwarder function.

Why the other options are wrong

  • A. Alerts are generated and managed at the search head, not by the universal forwarder.
  • C. Data obfuscation or hiding is not a built-in capability of the universal forwarder.

Question 3

In case of a conflict between a whitelist and a blacklist input setting, which one is used?

  1. Blacklist
  2. Whitelist
  3. They cancel each other out.
  4. Whichever is entered into the configuration first.
Show answer and explanation

Correct answer: A. Blacklist

When there is a conflict between whitelist and blacklist settings, the blacklist takes precedence. This means items on the blacklist will be excluded even if they appear on a whitelist, implementing a deny-first security model.

Why the other options are wrong

  • B. The whitelist does not override the blacklist; the opposite is true.
  • C. They do not cancel each other out; one has priority over the other.
  • D. The order of entry in the configuration file does not determine which takes precedence; blacklist always wins.

See all 10 free questions Get the full pack, US$39

209 practice questions for Splunk Enterprise Certified Admin (SPLK-1003), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 209 questions across all eight SPLK-1003 exam topics
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A failed SPLK-1003 attempt costs US$130, plus the time it takes to prepare again. This pack is US$39, paid once, and refunded if you fail.

Try 10 questions free before you buy.

Last updated September 2026 · 209 questions

What makes the SPLK-1003 hard

SPLK-1003 is a 60 minute, 56 question exam that goes deep on the operational side of Splunk: license management, indexers, search heads, configuration files, forwarders, clustering and data inputs. It covers a lot of ground in a short time, and Splunk does not publish a passing score for it, so there is no published margin to aim for.

Passing SPLK-1003 is also a prerequisite for the Splunk Enterprise Certified Architect track, so the material in this pack carries forward into that exam as well.

About the exam

The Splunk Enterprise Certified Admin validates the ability to manage, monitor and troubleshoot a Splunk Enterprise environment: license management, configuration files, distributed search, forwarder deployment and clustering. It is the prerequisite for the Splunk Enterprise Certified Architect track.

Exam domains

  • License management
  • Splunk apps and configuration files
  • Users, roles and authentication
  • Getting data in: inputs, forwarders and parsing
  • Distributed search
  • Introduction to Splunk clusters
  • Deploy and manage forwarders
  • Monitor and troubleshoot Splunk

56 questions, 60 minutes, taken at a Pearson VUE test centre or online proctored, US$130 per attempt. Splunk does not publish a passing score for this exam.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the Splunk SPLK-1003 pack?

209 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.