Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCore Certified Power User

Domain 4Objective 1

Perform Regex Field Extractions Using the Field Extractor (FX) SPLK-1002 Practice Questions (Page 2)

Part of the Creating and Managing Fields domain, which accounts for 10% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~3–4 in this domain), expect 2–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
6concepts
10%of the exam

Questions 6–10

  1. 6application · medium

    A Splunk admin is using the Field Extractor to create a regex extraction for a field called 'session_id' in web logs. The logs contain lines like: session=abc123xyz. The admin highlights 'abc123xyz' in the sample event, and the FX generates the regex: (?<session_id>[a-z0-9]+). The preview shows the field correctly on the sample event. However, when the admin tests the extraction on a different event with the session ID 'ABC123XYZ', the field does not appear. What is the most likely reason?

    Select an answer first
  2. 7foundation · easy

    What does the preview pane in the Field Extractor show?

    Select an answer first
  3. 8foundation · easy

    In the Field Extractor, after the initial regex is generated, what can a user do to improve the extraction accuracy?

    Select an answer first
  4. 9expert · medium

    A Splunk admin is creating a regex field extraction for a field called 'user_email' in authentication logs. The logs contain lines like: user=j.doe@example.com action=login. The admin selects 10 sample events that all have the same format and completes the extraction. After saving, the admin notices that the field is not appearing on all events of the sourcetype. The admin suspects the sample events were not representative. Which of the following is the most effective way to improve the extraction?

    Select an answer first
  5. 10foundation · easy

    When using the Field Extractor, why is it important to select sample events that represent the data pattern you want to extract?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.