
SplunkCore Certified Advanced Power User
Domain 3Objective 2
Referencing Lookups in Alerts core-certified-advanced-power-user Practice Questions (Page 2)
Part of the Alerts and Search Macros domain, which makes up ~30% of our current practice bank. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 10 practice questions to prepare you well beyond it. (estimate)
10questions here
2free pages
4concepts
Questions 6–10
- 6
An alert that uses a lookup to enrich results with a `team` field is failing with the error 'Lookup table 'team_lookup' does not exist.' The lookup definition `team_lookup` was created in the app `my_app`. The alert is running in the app `search`. What is the most likely cause of this error?
Select an answer first - 7
A scheduled alert that uses a lookup to enrich results with a `priority` field has been failing intermittently. The alert search is: `index=main | lookup priority_lookup host OUTPUT priority | where priority="high"`. The lookup definition `priority_lookup` is configured with a max matches of 1. Some hosts appear multiple times in the lookup file with different priorities. What is the most likely cause of the intermittent failures?
Select an answer first - 8
A user reports that a scheduled alert stopped working after a recent change. The alert search includes a `lookup` command that references a lookup definition named `device_registry`. The lookup definition was recently edited to change the field name `device_id` to `device_name` in the underlying CSV file. The alert search still uses `device_id` in the lookup command. What is the most likely cause of the alert failure?
Select an answer first - 9
When a lookup in an alert action fails because a field in the alert results does not exist in the lookup, what is the typical outcome?
Select an answer first - 10
In Splunk, where is a lookup definition typically created so that it can be referenced in alert actions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to core-certified-advanced-power-user
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “core-certified-advanced-power-user” is a trademark of its owner, used for identification only.