
SplunkEnterprise Certified Admin
Domain 5Objective 5
Explain How Data Transformations Are Defined and Invoked SPLK-1003 Practice Questions (Page 2)
Part of the Parsing and Data Manipulation domain, which makes up ~29% of our current practice bank. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 14 practice questions to prepare you well beyond it. (estimate)
14questions here
3free pages
5concepts
Questions 6–10
- 6
If a props.conf stanza has `TRANSFORMS-set1 = t1, t2, t3`, in what order will the transformations run?
Select an answer first - 7
A Splunk admin wants to use a lookup transformation to add a field to incoming events. The admin has created the lookup file and defined the transform in transforms.conf. What else is required to make the lookup work?
Select an answer first - 8
A Splunk admin needs to remove a prefix from a field value in incoming events. For example, change 'USER:alice' to 'alice'. Which type of transformation is best suited for this task?
Select an answer first - 9
A Splunk admin wants to use a regex transformation to extract a session ID from incoming events. The admin has created the transform in transforms.conf. What else must be done to ensure the transformation is applied to the correct sourcetype?
Select an answer first - 10
How are data transformations invoked during the parsing process in Splunk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1003” is a trademark of its owner, used for identification only.