
SplunkCloud Certified Admin
Domain 9Objective 2
Configure Input Phase Options, Such as Sourcetype Fine-Tuning and Character Set Encoding CLOUD-CERTIFIED-ADMIN Practice Questions (Page 1)
Part of the Fine-tuning Inputs domain, which accounts for 5% of the CLOUD-CERTIFIED-ADMIN exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–3 in this domain), expect 1–2 from this objective — we provide 8 practice questions to prepare you well beyond it. (estimate)
8questions here
2free pages
3concepts
5%of the exam
Questions 1–5
- 1
A Splunk admin is troubleshooting an input where events are being indexed with incorrect timestamps. The log format uses a custom timestamp pattern. Which input phase option should be configured to correctly extract the timestamp?
Select an answer first - 2
A Splunk admin is ingesting logs from a legacy system that outputs data in a mix of UTF-8 and UTF-16LE files. The admin has created a single sourcetype for all these files. The UTF-16LE files are not being parsed correctly, showing garbled characters. The admin needs to fix this without creating multiple sourcetypes. What should the admin do?
Select an answer first - 3
A Splunk admin notices that events from a custom application are being parsed with the wrong field extractions. The data is not a standard format like syslog or JSON. What is the most appropriate way to ensure the data is parsed correctly?
Select an answer first - 4
A data input contains text encoded in UTF-16, but Splunk is interpreting it as UTF-8, causing garbled characters in indexed events. Which setting should be configured on the input to fix this?
Select an answer first - 5
An admin is setting up a new data input for a web server that logs requests in a custom format. The default sourcetype is not correctly identifying the fields, and the admin wants to create a new sourcetype that will parse the logs accurately. Which steps should the admin take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CLOUD-CERTIFIED-ADMIN” is a trademark of its owner, used for identification only.