Creating Field Aliases and Calculated Fields for Splunk Core Certified Power User
This page covers the Creating Field Aliases and Calculated Fields domain of the Splunk Core Certified Power User certification. Master Cybersecurity offers 22 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
Which of the following knowledge objects represents the output of an eval expression?- A. Eval fields
- B. Calculated fields
- C. Field extractions
- D. Calculated lookups
Explanation
The correct answer is: B. Calculated fields.
A calculated field is the knowledge object whose value comes from an eval expression, evaluated at search time so the field appears in results as though it had been extracted from the data. Defining one means naming the field and supplying the expression, after which every search against the matching host, source, or sourcetype gains that field automatically. Eval fields is not a Splunk knowledge object name, though the phrase is a natural guess given the underlying command. Field extractions produce fields by pulling values out of the raw event text, using either a delimiter or a regular expression, so they read data rather than compute from it. Calculated lookups is not an object type either, since lookups enrich events by matching against an external table or collection, and while automatic lookups apply without being invoked, none of them evaluates an eval expression.
Question 2
Which of the following statements describe calculated fields? (Choose all that apply.)- A. Calculated fields can be used in the search bar.
- B. Calculated fields can be based on an extracted field.
- C. Calculated fields can only be applied to host and sourcetype.
- D. Calculated fields are shortcuts for performing calculations using the eval command.
Explanation
The correct answers are: A. Calculated fields can be used in the search bar., B. Calculated fields can be based on an extracted field., D. Calculated fields are shortcuts for performing calculations using the eval command..
Calculated fields behave like any other search-time field once defined, so they can be referenced in the search bar exactly as an extracted field would be, including in filters, eval expressions, and aggregations. They can be based on extracted fields, which follows from the search-time sequence, because extractions and aliases resolve before calculated fields and their values are therefore available to the expression. And they are precisely a shortcut for repetitive eval work, letting you define a calculation once in configuration instead of retyping the same clause in every search. The statement that they apply only to host and sourcetype is too narrow, since a calculated field can be scoped to a source as well, and scoping is what determines which events receive the field. That choice is made when the field is defined and is what keeps a calculation from reaching unrelated data.
Question 3
Calculated fields can be based on which of the following?- A. Tags
- B. Extracted fields
- C. Output fields for a lookup
- D. Fields generated from a search string
Explanation
The correct answer is: B. Extracted fields.
Splunk applies search-time knowledge objects in a fixed sequence: field extractions first, then field aliases, then calculated fields, then lookups, then event types, and finally tags. A calculated field is an eval expression evaluated during that third step, so the only values available to it are the ones produced earlier in the chain, which is why extracted fields are a valid basis. Output fields from a lookup are not available, because lookups are resolved after calculated fields have already been computed. Tags are applied at the very end of the sequence and carry no values an eval expression could operate on. Fields generated from a search string are also unavailable, since the entire search-time knowledge object chain completes before the SPL pipeline begins executing, so an eval or rex further down the search cannot feed a calculated field definition.
Question 4
A field alias has been created based on an original field. A search without any transforming commands is then executed in Smart Mode. Which field name appears in the results?- A. Both will appear in the All Fields list, but only if the alias is specified in the search.
- B. Both will appear in the Interesting Fields list, but only if they appear in at least 20 percent of events.
- C. The original field only appears in All Fields list and the alias only appears in the Interesting Fields list.
- D. The alias only appears in the All Fields list and the original field only appears in the Interesting Fields list.
Explanation
The correct answer is: B. Both will appear in the Interesting Fields list, but only if they appear in at least 20 percent of events..
Both the original field and its alias are present in the results, because an alias adds a second name rather than replacing the first, and Smart Mode with no transforming commands returns events with their fields intact. Where they appear in the sidebar depends on how common they are: Splunk lists a field under Interesting Fields when it occurs in at least twenty percent of the events returned, and under All Fields otherwise. So both names surface together, subject to that same threshold. The option requiring the alias to be named in the search is wrong, since an alias is applied automatically by its configuration and needs no mention to take effect. The two options that split the names between the lists are wrong as well, because nothing distinguishes an alias from an original field for that classification; each is judged on its own prevalence in the result set.
Question 5
Which of the following statements describes field aliases?- A. Field alias names replace the original field name.
- B. Field aliases can be used in lookup file definitions.
- C. Field aliases only normalize data across sources and sourcetypes.
- D. Field alias names are not case sensitive when used as part of a search.
Explanation
The correct answer is: B. Field aliases can be used in lookup file definitions..
Field aliases are usable in lookup definitions because of where they fall in the search-time sequence, which runs extractions first, aliases second, calculated fields third, and lookups fourth. By the time an automatic lookup is resolved, any alias has already been applied, so the aliased name is available to serve as the lookup's input field. The statement that aliases only normalize data across sources and sourcetypes fails on the word only: cross-source normalization is the most common motivation, but an alias is equally valid for giving a single sourcetype's cryptic field a readable second name. An alias also does not replace the original field name; it adds an additional name, and both the original and the alias remain searchable, which is what makes aliasing non-destructive. Field names in Splunk are case sensitive, so an alias must be referenced with exactly the capitalization it was defined with.
Other Splunk Core Certified Power User domains
- Correlating Events (24 questions)
- Creating and Managing Fields (21 questions)
- Creating and Using Macros (20 questions)
- Creating and Using Workflow Actions (25 questions)
- Creating Data Models (27 questions)
- Creating Tags and Event Types (21 questions)
- Filtering and Formatting Results (27 questions)
- Using the Common Information Model (CIM) (17 questions)
- Using Transforming Commands for Visualizations (19 questions)