Skip to content

O11y Cloud Certified Metrics User Practice Questions

Prepare for SPLK-4001 with more than an answer.

204 questions in the full set20 sample questionsUpdated Jan 26, 2026
Exam fee
$130 USD
Level
Entry
Valid for
3 years
Domains covered on the exam 10
  1. Using Transforming Commands for Visualizations10%
  2. Filtering and Formatting Results10%
  3. Correlating Events10%
  4. Creating and Managing Fields10%
  5. Creating Field Aliases and Calculated Fields10%
  6. Creating Tags and Event Types10%
  7. Creating and Using Macros10%
  8. Creating and Using Workflow Actions10%
  9. Creating Data Models10%
  10. Using the Common Information Model (CIM) Add-On10%
  1. 1

    A team has defined two macros:

    1. get_web_traffic = index=web sourcetype=access_combined
    2. successful_requests(1) = status=$status_code$

    How would a Power User correctly invoke these macros to search for all successful web traffic with a status code of 200?

    Show answer details

    Correct answer: C

    Macros are invoked by enclosing their names in backticks (``). When a macro accepts arguments, the values are passed within parentheses, like a function call. This search correctly invokes the first macro to define the base search and then invokes the second macro, passing 200 as the value for the status_code argument.

  2. 2

    The main difference between the chart and timechart commands is that timechart automatically uses _time as the x-axis and buckets the data into time-based spans.

    Show answer details

    Correct answer: A

    This statement is true. timechart is a specialized version of chart designed for time-series data. It automatically uses the _time field for the x-axis and groups data into time buckets (spans), which can be controlled with the span argument. The chart command is more general and can use any field for its x-axis.

  3. 3

    You are analyzing sales data and want to compare this week's daily sales count to last week's daily sales count in a single timechart. Which command is used to achieve this?

    Show answer details

    Correct answer: C

    The timewrap command is specifically designed to compare data over different time periods. After creating a daily timechart (timechart span=1d count), piping the results to timewrap w will create series for the current week (latest_week), the previous week (1week_before), and so on, allowing for direct comparison on a single chart.

  4. 4

    A Power User is building a dashboard for network operations that displays data from firewall logs. One field, fw_interface_name, contains values like ethernet1/1 and ethernet1/2. For readability, the user wants to display these as Public Facing and Internal DMZ respectively, without changing the underlying data. Which knowledge object is the best choice to accomplish this?

    Show answer details

    Correct answer: C

    A lookup is the ideal solution for enriching data with descriptive names based on a key field. A CSV file can be created mapping fw_interface_name to a new field like friendly_name. This can then be configured as an automatic lookup to add the friendly_name field to events at search time. This is more scalable and manageable than a long case() statement in a calculated field, and a field alias cannot change the value, only rename the field.

  5. 5

    When creating a Search workflow action, it is a best practice to select 'Run in new browser window' to avoid losing the context of the original search results.

    Show answer details

    Correct answer: A

    This is a best practice for usability. When a user is investigating an event, they often want to drill down into related data without losing their place. Configuring the Search workflow action to open in a new window or tab allows them to explore the new search results while keeping the original event context visible in the first window.

  6. 6

    A financial services company is analyzing VPN logs to track user session durations. The logs contain a user_id, event_type (with values 'login' and 'logout'), and timestamp. The analyst needs to calculate the duration of each session. The following two searches are proposed. Which statement accurately compares them?

    Search A:
    index=vpn sourcetype=vpn_logs | transaction user_id startswith="event_type=login" endswith="event_type=logout" | table user_id, duration

    Search B:
    index=vpn sourcetype=vpn_logs | stats first(_time) as start_time, last(_time) as end_time by user_id | eval duration = end_time - start_time | table user_id, duration

    Show answer details

    Correct answer: B

    While both searches can achieve the goal, Search B using stats is far more efficient. The stats command is a streaming command that processes events as they are retrieved and is highly optimized for this type of aggregation. The transaction command is a non-streaming command that must hold all events in memory to group them, making it resource-intensive and much slower, especially with large datasets or long-running transactions.

  7. 7

    A Power User is creating a macro named get_error_details(1) that accepts a single argument, error_code. The user wants to ensure that if the macro is called without an argument, it defaults to searching for error_code=5* and also validates that any provided argument is a number. Which macro definition correctly implements this?

    Show answer details

    Correct answer: D

    This question tests a subtle but important limitation of Splunk macros. While you can define arguments and provide a validation expression, there is no built-in syntax to provide a default value within the macro definition itself if the argument is not supplied. The coalesce approach in another option is a valid workaround within the search string, but it cannot be part of the core macro definition for handling a missing argument. Therefore, it's not possible to achieve both goals (default value and validation) through the standard macro settings.

  8. 8

    An analyst is tasked with normalizing firewall data from three different vendors (Palo Alto, Cisco, Check Point) to the Splunk Common Information Model (CIM). The data has been ingested, but searches against the Network_Traffic data model are not returning events from the Cisco source type.

    Which of the following are necessary troubleshooting steps to ensure the Cisco data is CIM compliant? (Select THREE)

    Show answer details

    Correct answer: A, B, D

  9. 9

    A Power User has created a data model for web access logs that is now being used in several critical dashboards. Users report that dashboards powered by this data model are loading very slowly. Which action would provide the most significant performance improvement for these dashboards?

    Show answer details

    Correct answer: B

    Data model acceleration creates a separate, summarized copy of the data on the indexers. When pivot-based searches run against an accelerated data model, they query this smaller, optimized summary instead of the raw data, resulting in a massive performance increase. The summary range should be set to cover the time period most frequently queried by the dashboards.

  10. 10

    True or False: A calculated field's eval expression is processed at index time, making it more performant for searches than using the eval command directly in the search string.

    Show answer details

    Correct answer: B

    This statement is false. Calculated fields are knowledge objects that are applied at search time, just like the eval command. They do not alter the raw data at index time. The primary benefit of a calculated field is reusability and consistency, not a performance gain from index-time processing.

Create an account to continue.