Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCore Certified Power User

Domain 4Objective 1

Perform Regex Field Extractions Using the Field Extractor (FX) SPLK-1002 Practice Questions (Page 4)

Part of the Creating and Managing Fields domain, which accounts for 10% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~3–4 in this domain), expect 2–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
6concepts
10%of the exam

Questions 16–20

  1. 16application · medium

    A Splunk admin is using the Field Extractor to create a regex extraction for a field called 'ip_address' in firewall logs. The admin highlights the IP address in the sample event, and the FX generates the regex: (?<ip_address>\d+\.\d+\.\d+\.\d+). The preview shows the field correctly on the sample event. However, when the admin tests the extraction on a different event with an IPv6 address, the field does not appear. What is the most likely reason?

    Select an answer first
  2. 17foundation · easy

    When saving a field extraction in the Field Extractor, what must the user specify?

    Select an answer first
  3. 18application · medium

    A Splunk admin is using the Field Extractor to create a regex extraction for a field called 'user_id' in application logs. The logs contain lines like: user=jsmith action=login. The admin highlights 'jsmith' in the sample event, and the FX generates the regex: (?<user_id>\w+). The preview shows the field correctly on the sample event. However, when the admin tests the extraction on a different event with the user ID 'j.smith', the field does not appear. What is the most likely reason?

    Select an answer first
  4. 19expert · medium

    A Splunk admin is using the Field Extractor to create a regex extraction for a field called 'request_id' in API logs. The admin highlights the request ID in the sample event, and the FX generates the regex: (?<request_id>[a-f0-9-]+). The preview shows the field correctly on the sample event. However, when the admin tests the extraction on a different event with the request ID 'ABCD-1234', the field does not appear. What is the most likely reason?

    Select an answer first
  5. 20application · medium

    A Splunk admin is using the Field Extractor to create a regex extraction for a field called 'transaction_id' in a log source. The admin selects 5 sample events that all have the same format and completes the extraction. After saving, the admin notices that the field is not appearing on all events of the sourcetype. What is the most likely reason?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to SPLK-1002

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.