
SplunkEnterprise Certified Admin
Domain 5Objective 3
Explain How Timestamps and Time Zones Are Extracted or Assigned to Events SPLK-1003 Practice Questions (Page 2)
Part of the Parsing and Data Manipulation domain, which makes up ~29% of our current practice bank. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 16 practice questions to prepare you well beyond it. (estimate)
16questions here
4free pages
5concepts
Questions 6–10
- 6
Which of the following is a valid timestamp configuration attribute in props.conf?
Select an answer first - 7
An admin is troubleshooting why a specific sourcetype's events have incorrect _time values. The raw events look like: 'May 14 08:23:45 host app[123]: error'. The admin has verified that the timestamp is being extracted correctly, but the _time is off by exactly 4 hours. What is the most likely cause?
Select an answer first - 8
During parsing, where does Splunk first look to extract an event's timestamp?
Select an answer first - 9
A Splunk admin is configuring a sourcetype for logs from a device that sends timestamps in UTC. However, the admin notices that the _time is off by one hour during the summer. The device does not send an offset in the timestamp. What is the most likely cause?
Select an answer first - 10
An admin is ingesting legacy application logs that do not contain any timestamp. The events are generated by a batch process that runs every night. The admin wants the _time to reflect the actual generation time, not the ingestion time. What is the most practical solution?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1003” is a trademark of its owner, used for identification only.