Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCore Certified Advanced Power User

Domain 3Objective 2

Referencing Lookups in Alerts core-certified-advanced-power-user Practice Questions (Page 2)

Part of the Alerts and Search Macros domain, which makes up ~30% of our current practice bank. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 10 practice questions to prepare you well beyond it. (estimate)

10questions here
2free pages
4concepts

Questions 6–10

  1. 6expert · hard

    An alert that uses a lookup to enrich results with a `team` field is failing with the error 'Lookup table 'team_lookup' does not exist.' The lookup definition `team_lookup` was created in the app `my_app`. The alert is running in the app `search`. What is the most likely cause of this error?

    Select an answer first
  2. 7expert · hard

    A scheduled alert that uses a lookup to enrich results with a `priority` field has been failing intermittently. The alert search is: `index=main | lookup priority_lookup host OUTPUT priority | where priority="high"`. The lookup definition `priority_lookup` is configured with a max matches of 1. Some hosts appear multiple times in the lookup file with different priorities. What is the most likely cause of the intermittent failures?

    Select an answer first
  3. 8expert · hard

    A user reports that a scheduled alert stopped working after a recent change. The alert search includes a `lookup` command that references a lookup definition named `device_registry`. The lookup definition was recently edited to change the field name `device_id` to `device_name` in the underlying CSV file. The alert search still uses `device_id` in the lookup command. What is the most likely cause of the alert failure?

    Select an answer first
  4. 9foundation · easy

    When a lookup in an alert action fails because a field in the alert results does not exist in the lookup, what is the typical outcome?

    Select an answer first
  5. 10foundation · easy

    In Splunk, where is a lookup definition typically created so that it can be referenced in alert actions?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “core-certified-advanced-power-user” is a trademark of its owner, used for identification only.