95 practice questions for Splunk Core Certified Advanced Power User (SPLK-1004), with full explanations.
Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.
- 95 questions across all 22 SPLK-1004 blueprint topics
- Answers and explanations for every question, including the wrong options
- A questions-only PDF for timed practice runs
- Instant delivery by email the moment you check out
- Free monthly updates for as long as the exam is live
- Pass or your money back
A SPLK-1004 attempt costs US$130. This pack is US$39, paid once.
Try 10 questions free before you buy.
Last updated September 2026 · 95 questions
What makes the SPLK-1004 hard
SPLK-1004 sits between Power User and the admin track, and it is the exam Splunk built for people who write the searches everyone else copies. It is 70 questions in 60 minutes, which is the tightest pace of any Splunk exam, less than a minute a question, and the blueprint is unusually granular: 22 topic areas, none worth more than 7%, so there is no single domain to cram and no domain to skip. Splunk Core Certified Power User is the prerequisite.
The marks cluster in three places. The largest topics are multivalued fields at 7% with makemv, mvexpand and the mv eval functions, drilldowns at 7% with predefined tokens and dynamic and contextual drilldowns, and the 6% group: manipulating and filtering data with bin, xyseries, untable and foreach, subsearches with their limits and when not to use them, improving dashboard performance with tstats and base and post process searches, and customising dashboards.
The search efficiency block covers architecture components, search flow, streaming versus transforming commands, command ordering, the job inspector, pre-filtering, lispy and the TERM directive. The acceleration block covers report acceleration and summary indexing, then data models, tsidx files and tstats and how to choose between them. The knowledge object block covers advanced lookups including KV Store, external and geospatial, alerts with webhooks and log events, field extraction with the Field Extractor, rex and erex, self-describing data with spath and multikv, and nested macros.
The statistics and eval blocks cover eventstats, streamstats, appendpipe, fieldsummary and the eval function families. Dashboards round it out: Simple XML prototypes, forms and tokens with cascading inputs, event handlers and Simple XML extensions. Expect questions that show a search and ask which command was missing or misordered.
About the exam
SPLK-1004 (Splunk Core Certified Advanced Power User) is an intermediate-level certification for authoring complex searches and reports, implementing advanced knowledge objects and building well-performing dashboards on Splunk Enterprise and Splunk Cloud. Prerequisite: Splunk Core Certified Power User (SPLK-1002).
Exam domains
- Statistical commands 4%, eval functions 4%, lookups 4%, alerts 4%, advanced field creation 4%
- Self-describing data 3%, advanced search macros 3%
- Acceleration: reports and summary indexing 4%; data models and tsidx files 4%
- Using search efficiently 4%, more search tuning 3%
- Manipulating and filtering data 6%, multivalued fields 7%, advanced transactions 5%, working with time 2%, subsearches 6%
- Dashboards: creating a prototype 4%, using forms 5%, improving performance 6%, customising dashboards 6%, adding drilldowns 7%, advanced behaviours and visualisations 5%
70 multiple-choice questions, 60 minutes, US$130 per attempt, taken at a Pearson VUE test centre or online proctored. Splunk does not publish a passing score for this exam. Certification valid for three years.









Reviews
There are no reviews yet.