
SplunkCore Certified Power User
Domain 3Objective 5
Report on Transactions SPLK-1002 Practice Questions (Page 3)
Part of the Correlating Events domain, which accounts for 15% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
6concepts
15%of the exam
Questions 11–15
- 11
Which of the following fields is automatically generated by the transaction command?
Select an answer first - 12
A data engineer needs to correlate events by a `request_id` field and also needs to calculate the total time between the first and last event for each request. The dataset is very large, and performance is a concern. Which approach is most appropriate?
Select an answer first - 13
A security analyst needs to correlate all authentication events for a single user session. The logs contain a session ID field, and each event has a timestamp. The analyst wants to group events that share the same session ID and occurred within 30 minutes of each other. Which transaction command should be used?
Select an answer first - 14
Why can the transaction command be resource-intensive on large datasets?
Select an answer first - 15
Which transaction option is used to limit the total time span of a transaction?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.