SPLUNK · SPLK-1004

Splunk SPLK-1004 Exam Practice Questions

95 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 95 questions in this pack

Question 1

Which statement about tsidx files is accurate?

  1. Splunk updates tsidx files every 30 minutes.
  2. Splunk removes outdated tsidx files every 5 minutes.
  3. A tsidx file consists of a lexicon and a posting list.
  4. Each bucket in each index may contain only one tsidx file.
Show answer and explanation

Correct answer: C. A tsidx file consists of a lexicon and a posting list.

A tsidx file is Splunk's time-series index file that consists of two main components: a lexicon (vocabulary of terms) and a posting list (locations where those terms appear in the data). This structure enables fast searching and retrieval of events from buckets.

Why the other options are wrong

  • A. Splunk does not update tsidx files on a fixed 30-minute schedule; updates occur based on bucket rolling and data ingestion.
  • B. Tsidx files are not automatically removed every 5 minutes; they persist with their associated buckets according to retention policies.
  • D. Each bucket can contain multiple tsidx files, particularly when dealing with different index structures or optimization scenarios.

Question 2

Repeating JSON data structures within one event will be extracted as what type of fields?

  1. Single value
  2. Lexicographical
  3. Multivalue
  4. Mvindex
Show answer and explanation

Correct answer: C. Multivalue

When JSON data contains repeating structures (arrays or multiple instances of the same key-value pairs), Splunk automatically extracts these as multivalue fields, allowing each value to be indexed and searched individually within the field.

Why the other options are wrong

  • A. Single value fields cannot represent repeating structures; multivalue fields are required.
  • B. Lexicographical refers to ordering, not a field type used for JSON extraction.
  • D. Mvindex is a function used to access multivalue fields, not a field type itself.

Question 3

What default Splunk role can use the Log Event alert action?

  1. Power
  2. User
  3. can_delete
  4. Admin
Show answer and explanation

Correct answer: D. Admin

The Log Event alert action requires the edit_log_alert_event capability, and in the shipped authorize.conf that capability is assigned only to the admin role. Any other role must be explicitly granted the capability before it can log events from an alert. Because the question asks which default role can use the action out of the box, admin is the correct choice.

Why the other options are wrong

  • A. The power role does not include edit_log_alert_event by default, so power users cannot run the Log Event alert action without an added capability.
  • B. The user role has the most restricted capability set and does not include edit_log_alert_event.
  • C. can_delete is a default role, but it exists solely to grant delete_by_keyword and carries no alert action capabilities.

See all 10 free questions Get the full pack, US$39

95 practice questions for Splunk Core Certified Advanced Power User (SPLK-1004), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 95 questions across all 22 SPLK-1004 blueprint topics
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A SPLK-1004 attempt costs US$130. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 95 questions

What makes the SPLK-1004 hard

SPLK-1004 sits between Power User and the admin track, and it is the exam Splunk built for people who write the searches everyone else copies. It is 70 questions in 60 minutes, which is the tightest pace of any Splunk exam, less than a minute a question, and the blueprint is unusually granular: 22 topic areas, none worth more than 7%, so there is no single domain to cram and no domain to skip. Splunk Core Certified Power User is the prerequisite.

The marks cluster in three places. The largest topics are multivalued fields at 7% with makemv, mvexpand and the mv eval functions, drilldowns at 7% with predefined tokens and dynamic and contextual drilldowns, and the 6% group: manipulating and filtering data with bin, xyseries, untable and foreach, subsearches with their limits and when not to use them, improving dashboard performance with tstats and base and post process searches, and customising dashboards.

The search efficiency block covers architecture components, search flow, streaming versus transforming commands, command ordering, the job inspector, pre-filtering, lispy and the TERM directive. The acceleration block covers report acceleration and summary indexing, then data models, tsidx files and tstats and how to choose between them. The knowledge object block covers advanced lookups including KV Store, external and geospatial, alerts with webhooks and log events, field extraction with the Field Extractor, rex and erex, self-describing data with spath and multikv, and nested macros.

The statistics and eval blocks cover eventstats, streamstats, appendpipe, fieldsummary and the eval function families. Dashboards round it out: Simple XML prototypes, forms and tokens with cascading inputs, event handlers and Simple XML extensions. Expect questions that show a search and ask which command was missing or misordered.

About the exam

SPLK-1004 (Splunk Core Certified Advanced Power User) is an intermediate-level certification for authoring complex searches and reports, implementing advanced knowledge objects and building well-performing dashboards on Splunk Enterprise and Splunk Cloud. Prerequisite: Splunk Core Certified Power User (SPLK-1002).

Exam domains

  • Statistical commands 4%, eval functions 4%, lookups 4%, alerts 4%, advanced field creation 4%
  • Self-describing data 3%, advanced search macros 3%
  • Acceleration: reports and summary indexing 4%; data models and tsidx files 4%
  • Using search efficiently 4%, more search tuning 3%
  • Manipulating and filtering data 6%, multivalued fields 7%, advanced transactions 5%, working with time 2%, subsearches 6%
  • Dashboards: creating a prototype 4%, using forms 5%, improving performance 6%, customising dashboards 6%, adding drilldowns 7%, advanced behaviours and visualisations 5%

70 multiple-choice questions, 60 minutes, US$130 per attempt, taken at a Pearson VUE test centre or online proctored. Splunk does not publish a passing score for this exam. Certification valid for three years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the Splunk SPLK-1004 pack?

95 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.