DEV Community

Cover image for Splunk Advanced Power User 1004: A Hands-On SPL Self-Check Before You Book
Palak Mazumdar
Palak Mazumdar

Posted on

Splunk Advanced Power User 1004: A Hands-On SPL Self-Check Before You Book

The Splunk Advanced Power User 1004 exam (SPLK-1004) checks whether you can write and tune intermediate-to-advanced SPL and build interactive dashboards. You get 70 multiple-choice questions in 60 minutes for USD 130 per attempt, and you must already hold the Splunk Core Certified Power User badge, according to Splunk's certification track page for the Advanced Power User.

Most guides stop at those numbers. This one doesn't. Below you'll find short searches and dashboard snippets, one for each cluster of the blueprint. If you can explain what each one returns without running it, you're close. If you hesitate, you've found where your study time should go.

Why can't you skip any topic on SPLK-1004?

You can't skip one because no single topic is big enough to carry you. The Advanced Power User test blueprint PDF splits the exam into 22 topics, and the largest of them, multivalued fields and drilldowns, weigh only 7% each. The smallest, Working with Time, is 2%.

Group the topics and a clearer picture appears. Topics 1.0 to 16.0 (statistics, eval, lookups, alerts, field extraction, acceleration, search tuning, transactions and subsearches) add up to 67%. Topics 17.0 to 22.0 (prototypes, forms, dashboard performance, customization, drilldowns and advanced behaviors) add up to the remaining 33%.

SPLK-1004 blueprint drawn as a 22-channel mixing desk: each fader is one topic, set to its exam weight, with search skills on the left bus (67%) and dashboard skills on the right bus (33%)

The practical takeaway: a candidate who is strong on searching but has never edited Simple XML gives away about a third of the exam. The reverse is just as costly. CertFun lays every subtopic out in one list in its SPLK-1004 syllabus with all 22 weighted topics, which is handy for ticking items off as you go.

Note: the blueprint says total exam time includes 3 minutes to review the exam agreement, so your real answering time is closer to 57 minutes.

Can you tell eventstats from streamstats at a glance?

You should be able to, because blueprint topic 1.0 lists both, and the difference is a favorite source of distractor answers. Read these two searches and predict the output.

index=web sourcetype=access_combined
| eventstats avg(bytes) AS avg_bytes BY host
| where bytes > 2 * avg_bytes
Enter fullscreen mode Exit fullscreen mode
index=web sourcetype=access_combined
| sort 0 _time
| streamstats count AS hit_number BY clientip
Enter fullscreen mode Exit fullscreen mode

The first keeps every event, adds the per-host average to each one, then filters to oversized responses. The second numbers each client's hits in time order, so the third request from an IP gets hit_number=3. Neither one collapses events the way stats does. If you'd have answered "it returns one row per host" for the first search, revisit the stats family before anything else.

Prerequisite material matters here. Splunk expects the basics of stats, timechart and lookups from the earlier exam, so if those feel rusty, skim the Core Certified Power User exam overview and its topic list first.

What happens to a multivalue field after mvexpand?

Each value becomes its own event, and every other field is copied onto each new event. Multivalued fields (topic 13.0) are one of the two heaviest topics at 7%, so expect several questions here.

| makeresults
| eval recipients="ana@example.com;raj@example.com;li@example.com"
| makemv delim=";" recipients
| mvexpand recipients
Enter fullscreen mode Exit fullscreen mode

This returns three results, one per address. Swap the last line for | eval n=mvcount(recipients) and you get a single result with n=3. Know the difference between makemv (splits one string into a multivalue field), mvexpand (splits one event into many) and the mv* eval functions (work inside a single event).

Self-describing data (topic 6.0) is close kin. Try predicting this one:

| makeresults
| eval payload="{\"user\":{\"id\":42,\"roles\":[\"admin\",\"auditor\"]}}"
| spath input=payload path=user.roles{} output=roles
Enter fullscreen mode Exit fullscreen mode

roles comes back as a multivalue field holding admin and auditor. The {} suffix is what tells spath to walk the array.

When does tstats beat a normal search?

tstats wins when the data it needs already sits in tsidx files, either indexed fields or an accelerated data model. Topics 8.0, 9.0 and 19.0 all touch acceleration, so this idea pays off three times.

| tstats count FROM datamodel=Web WHERE Web.status=404 BY _time Web.src span=1h
Enter fullscreen mode Exit fullscreen mode

This assumes an accelerated Web data model. It counts 404s per source per hour without reading raw events, which is why it's fast. Be ready to answer the reverse question too: why does tstats return nothing for a field that only exists at search time? Because that field was never written to a tsidx file.

The official Splunk Advanced Power User learning path includes Data Models and Search Optimization courses that cover this in depth, and the blueprint names both among its suggested training.

Should you use a subsearch, a lookup or stats?

Pick the tool that avoids the subsearch whenever the data allows it. Topic 16.0 has a subtopic literally called "When NOT to use subsearch", which tells you how Splunk frames the question.

index=security sourcetype=firewall
    [ search index=threat_intel | fields src_ip | rename src_ip AS dest_ip ]
Enter fullscreen mode Exit fullscreen mode

That works, but subsearches have result and runtime limits, so a large threat list can be cut short without warning. If the list is static, a lookup is safer:

index=security sourcetype=firewall
| lookup bad_ips ip AS dest_ip OUTPUT threat_level
| where isnotnull(threat_level)
Enter fullscreen mode Exit fullscreen mode

The same logic applies to transaction (topic 14.0). When you only need a start time, an end time and the pages visited per session, stats is lighter:

index=web sourcetype=access_combined
| stats min(_time) AS start max(_time) AS finish values(uri_path) AS pages BY JSESSIONID
| eval duration = finish - start
Enter fullscreen mode Exit fullscreen mode

Search tuning (topic 11.0) rounds this out. index=net TERM(10.0.0.15) matches the IP as one indexed term instead of breaking it apart at the periods, which is the kind of detail a single question can hinge on. To see how Splunk phrases questions on these trade-offs, work through CertFun's free SPLK-1004 sample questions and note which ones you got right for the wrong reason.

Can you wire a token from a dropdown to a drilldown?

If you can, you've covered most of the dashboard third of the exam. Forms (18.0), drilldowns (21.0) and advanced behaviors (22.0) all depend on tokens.

<input type="dropdown" token="host_tok">
  <label>Host</label>
  <fieldForLabel>host</fieldForLabel>
  <fieldForValue>host</fieldForValue>
  <search>
    <query>| tstats count WHERE index=web BY host</query>
  </search>
</input>
Enter fullscreen mode Exit fullscreen mode

A panel then uses $host_tok$ in its own query. For a drilldown that passes the clicked value to another panel:

<drilldown>
  <set token="clicked_ip">$click.value$</set>
</drilldown>
Enter fullscreen mode Exit fullscreen mode

Self-check questions to answer out loud: What's the difference between $click.value$ and $row.<fieldname>$? How does a base search with post-process searches cut load time (topic 19.0)? How do you make a second dropdown depend on the first (cascading inputs, 18.3)? If any of these stall you, build a small test dashboard on a free Splunk instance and break it on purpose.

Watch: a quick SPLK-1004 walkthrough

This short CertFun video covers the exam format and how to approach preparation.

How should you plan the last three weeks?

Spend the first two weeks on gaps and the last week on timed practice. A simple split that follows the 67/33 weighting:

Week Focus Done when you can...
1 Stats family, eval functions, multivalue fields, spath Predict the output of every snippet above without running it
2 Acceleration, tstats, subsearch limits, transactions, then forms, tokens and drilldowns Build a two-input dashboard with a working drilldown from scratch
3 Timed mixed sets and review of every wrong answer Finish 70 questions with time left to flag and revisit

Week 3 is where a timed SPLK-1004 practice exam earns its place: it tells you whether your accuracy holds for 70 questions in a row, not just for one snippet at a time.

Book your seat early so the date anchors the plan. A fixed date turns "I'll study tsidx files eventually" into a week-two task with a deadline.

Frequently Asked Questions

1. How many questions are on the Splunk Advanced Power User 1004 exam?

The SPLK-1004 exam has 70 multiple-choice questions and a 60-minute time limit. Splunk's blueprint notes that the 60 minutes include 3 minutes for reviewing the exam agreement.

2. Do I need the Power User certification before taking SPLK-1004?

Yes. Splunk lists the Splunk Core Certified Power User certification as the prerequisite for the Advanced Power User exam.

3. Which SPLK-1004 topics carry the most weight?

Working with Multivalued Fields and Adding Drilldowns are the largest topics at 7% each. Most of the other 20 topics sit between 3% and 6%, so breadth matters more than depth in any one area.

4. How much does the SPLK-1004 exam cost?

Splunk lists the price as USD 130 per exam attempt. You schedule and pay through Pearson VUE's Splunk testing page.

5. Is SPLK-1004 mostly about searching or about dashboards?

Both. Search-related topics (1.0 to 16.0) make up 67% of the blueprint, and dashboard topics (17.0 to 22.0) make up the other 33%.

Where to go from here

Run every snippet in this post against your own data, then rewrite it from memory a day later. That second attempt shows you what you actually know, and the gaps it exposes are your study list for the week.

For a broader roadmap covering courses, community resources and study habits, CertFun's step-by-step guide to earning the Advanced Power User certification picks up where this self-check leaves off.

Top comments (0)