
SplunkCore Certified Power User
Domain 6Objective 3
Create an Event Type SPLK-1002 Practice Questions (Page 1)
Part of the Creating Tags and Event Types domain, which accounts for 10% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~3–4 in this domain), expect 1–1 from this objective — we provide 13 practice questions to prepare you well beyond it. (estimate)
13questions here
3free pages
5concepts
10%of the exam
Questions 1–5
- 1
A Splunk admin creates an event type named 'high_priority_errors' with the search string `error_level=critical`. Later, they notice that some critical events are not being tagged. They want to modify the event type to also include `error_level=alert` without breaking existing searches that reference the event type name. What should they do?
Select an answer first - 2
A team has 50 event types, and several are outdated. The admin wants to identify which event types are no longer used in any saved searches or dashboards before deleting them. What is the most efficient way to determine usage?
Select an answer first - 3
A Splunk environment has an event type 'web_error' defined as `sourcetype=access_combined status>=400`. An analyst notices that some events with status=500 are not being tagged as 'web_error'. They also have an event type 'server_error' defined as `sourcetype=access_combined status=500` with a higher priority. What is the most likely reason for the missing tags?
Select an answer first - 4
A user wants to create an event type from a search they just ran. The search is `index=web status=404`. They want the event type to be named 'web_404_errors'. What is the correct way to do this from the search page?
Select an answer first - 5
An admin needs to delete an event type that was created by mistake. They want to ensure that no saved searches reference it before deletion. What is the safest way to proceed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.