Splunk SPLK-1002 Exam
Splunk Core Certified Power User (Page 8 )

Updated On: 4-Feb-2026

Which of the following searches will return events containing a tag named Privileged?

  1. tag=Priv
  2. tag=Priv*
  3. tag=priv*
  4. tag=privileged

Answer(s): B


Reference:

https://docs.splunk.com/Documentation/PCI/4.1.0/Install/PrivilegedUserActivity



Given the macro definition below, what should be entered into the Name and Arguments fields to correctly configure the macro?

  1. The macro name is sessiontracker and the arguments are action, JESSIONID.
  2. The macro name is sessiontracker(2) and the arguments are action, JESSIONID.
  3. The macro name is sessiontracker and the arguments are $action$, $JESSIONID$.
  4. The macro name is sessiontracker(2) and the Arguments are $action$, $JESSIONID$.

Answer(s): B


Reference:

https://docs.splunk.com/Documentation/Splunk/8.0.3/Knowledge/Definesearchmacros



What is required for a macro to accept three arguments?

  1. The macro's name ends with (3).
  2. The macro's name starts with (3).
  3. The macro's argument count setting is 3 or more.
  4. Nothing, all macros can accept any number of arguments.

Answer(s): A



Which workflow action method can be used when the action type is set to link?

  1. GET
  2. PUT
  3. Search
  4. UPDATE

Answer(s): A


Reference:

https://docs.splunk.com/Documentation/Splunk/8.0.3/Knowledge/SetupaGETworkflowaction



Viewing page 8 of 54
Viewing questions 29 - 32 out of 226 questions



Post your Comments and Discuss Splunk SPLK-1002 exam prep with other Community members:

Join the SPLK-1002 Discussion