Creating Data Models for Splunk Core Certified Power User

This page covers the Creating Data Models domain of the Splunk Core Certified Power User certification. Master Cybersecurity offers 27 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.

Sample Practice Questions

  1. Question 1

    Data models are composed of one or more of which of the following datasets? (Choose all that apply.)
    1. A. Events datasets
    2. B. Search datasets
    3. C. Transaction datasets
    4. D. Any child of event, transaction, and search datasets
    Explanation

    The correct answers are: A. Events datasets, B. Search datasets, C. Transaction datasets, D. Any child of event, transaction, and search datasets.

    A data model is built from all of these. The three root dataset types are events, searches, and transactions, and each can have child datasets that inherit from it, so children belong on the list as well. Root event datasets are the most common, defined by constraints that select a set of events. Root search datasets are defined by a search string instead, which suits cases where the data needs shaping before it enters the model. Root transaction datasets group related events into composite events using the fields and time constraints a transaction requires. Children extend any of these by adding further constraints, narrowing their parent's scope while inheriting its fields, which is how a model comes to have a hierarchy rather than a flat list. Because every option names a genuine component, the answer includes all of them.

  2. Question 2

    Which group of users would most likely use pivots?
    1. A. Users
    2. B. Architects
    3. C. Administrators
    4. D. Knowledge Managers
    Explanation

    The correct answer is: A. Users.

    Pivot exists for ordinary users, because its whole purpose is to let someone build a report or a chart from a data model without writing SPL. The interface presents the model's datasets and fields as choices to select, so the skill required is understanding the data rather than the search language. Architects, administrators, and knowledge managers are the roles more likely to build the data models Pivot consumes, which is the inverse of the relationship the question asks about, since they do the modelling work precisely so that users need not write searches. That division of labour is the point of the feature, because a knowledge manager encodes the structure once and a much larger population then explores it. Those roles can of course use Pivot too, but they are not the group it is aimed at.

  3. Question 3

    A data model consists of which three types of datasets?
    1. A. Constraint, field, value.
    2. B. Events, searches, transactions.
    3. C. Field extraction, regex, delimited.
    4. D. Transaction, session ID, metadata.
    Explanation

    The correct answer is: B. Events, searches, transactions..

    A data model is built from three dataset types: events, searches, and transactions. An event dataset selects a set of events using constraints, a search dataset is defined by a search string, and a transaction dataset groups related events into composite events. Any of the three can serve as a root, and each can have children that inherit its fields while narrowing its scope. Constraint, field, and value are components of a dataset rather than dataset types, since a root event dataset is made of constraints and fields. Field extraction, regex, and delimited describe methods of getting fields out of raw data, which is upstream of modelling entirely. Transaction, session ID, and metadata mixes one genuine dataset type with a field name and a general category, so it does not describe the set.

  4. Question 4

    Which of the following is the correct way to use the datamodel command to search fields in the Web data model within the Web dataset?
    1. A. | datamodel Web Web search | fields Web*
    2. B. | search datamodel Web Web | fields Web*
    3. C. | datamodel Web Web fields | search Web*
    4. D. datamodel=Web | search Web | fields Web*
    Explanation

    The correct answer is: A. | datamodel Web Web search | fields Web*.

    The datamodel command takes the model name, then the dataset name, then the keyword indicating what to do, so searching the Web dataset of the Web model means following the command with Web, Web, and search, after which the results can be narrowed with fields. That fixed argument order is what the question tests. The option leading with search treats datamodel as a search term rather than a command, so nothing would be retrieved from the model. The option placing fields before search reverses the keyword and the subsequent command, leaving datamodel without a valid final argument. And the option writing datamodel as a field comparison misunderstands the syntax entirely, because datamodel is a generating command that must begin the pipeline with a leading pipe rather than being compared to a value.

  5. Question 5

    Which of the following statements describe data model acceleration? (Choose all that apply.)
    1. A. Root events cannot be accelerated.
    2. B. Accelerated data models cannot be edited.
    3. C. Private data models cannot be accelerated.
    4. D. You must have administrative permissions or the accelerate_datamodel capability to accelerate a data model.
    Explanation

    The correct answers are: B. Accelerated data models cannot be edited., C. Private data models cannot be accelerated., D. You must have administrative permissions or the accelerate_datamodel capability to accelerate a data model..

    Three of these hold. An accelerated data model cannot be edited while acceleration is on, because the summary already built would no longer match a changed structure, so acceleration must be turned off before the model can be modified. A private data model cannot be accelerated either, since acceleration builds a shared summary on the indexers and that only makes sense for a model other users can reach, so the model must be shared first. And acceleration requires administrative permissions or the accelerate_datamodel capability, which exists because the summaries consume disk and generate ongoing background searches. The statement that root events cannot be accelerated is false and is in fact the opposite of the usual case, since root event datasets are the normal candidates for acceleration, while the type that cannot be accelerated is the transaction dataset.

Other Splunk Core Certified Power User domains

Practice all 27 Creating Data Models questions · Browse Splunk Core Certified Power User