Filtering and Formatting Results for Splunk Core Certified Power User
This page covers the Filtering and Formatting Results domain of the Splunk Core Certified Power User certification. Master Cybersecurity offers 27 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
Which one of the following statements about the search command is true?- A. It does not allow the use of wildcards.
- B. It treats field values in a case-sensitive manner.
- C. It can only be used at the beginning of the search pipeline.
- D. It behaves exactly like search strings before the first pipe.
Explanation
The correct answer is: D. It behaves exactly like search strings before the first pipe..
The search command behaves exactly as the terms before the first pipe do, which is the point of having it: the same syntax, the same wildcard support, and the same case-insensitivity for values apply whether you are writing the initial filter or filtering again later in the pipeline. That equivalence is why it is often used after a transforming command to narrow results without learning a second syntax. Wildcards are permitted, so the claim that they are not is wrong. Field values are matched case-insensitively rather than case-sensitively, though field names themselves are case sensitive, and that asymmetry is worth remembering. And the command is not restricted to the beginning of the pipeline, since being usable later is precisely what distinguishes it from the implicit search at the start.
Question 2
Which of the following actions can the eval command perform?- A. Remove fields from results.
- B. Create or replace an existing field.
- C. Group transactions by one or more fields.
- D. Save SPL commands to be reused in other searches.
Explanation
The correct answer is: B. Create or replace an existing field..
eval creates a new field or replaces an existing one, assigning it the result of an expression evaluated once per event. Assigning to a name that already exists overwrites it, which is a normal technique for cleaning or reformatting a value in place. Removing fields is done by the fields command with a minus sign rather than by eval, since eval only ever adds or overwrites. Grouping transactions by one or more fields is the job of transaction or stats, and eval has no ability to combine events at all because it works strictly within a single event. Saving SPL commands for reuse describes a macro, which packages search text rather than computing values. The reliable way to place eval is to remember that it produces a field on each event and nothing else.
Question 3
Where are the results of eval commands stored?- A. In a field.
- B. In an index.
- C. In a KV Store.
- D. In a database.
Explanation
The correct answer is: A. In a field..
The result of an eval expression is stored in a field, created on each event as the expression is evaluated at search time. That field then behaves like any other for the remainder of the pipeline, available to filters, aggregations, and further eval expressions. Nothing is written to an index, which is the important consequence: eval results exist only for the duration of the search, so re-running it recomputes them and editing the expression changes results immediately with no reindexing. The KV Store is a separate storage facility used by apps and lookup collections and is never an implicit destination for eval output. A database is not involved either, since Splunk stores indexed events in its own buckets rather than in a relational system, and eval results are not persisted anywhere at all.
Question 4
Which of the following can be used with the eval command tostring function? (Choose all that apply.)- A. "hex"
- B. "commas"
- C. "decimal"
- D. "duration"
Explanation
The correct answers are: A. "hex", B. "commas", D. "duration".
The tostring function takes an optional second argument naming the output format, and the accepted values are hex, commas, and duration. Passing hex renders a number in hexadecimal, commas inserts thousands separators for readability in a table, and duration converts a number of seconds into a readable span of hours, minutes, and seconds. decimal is not among them, which is the distinction being tested: producing a plain decimal string is what tostring does by default when no format argument is supplied, so no keyword is needed and none exists. Passing an unrecognised format produces an error rather than a silent fallback, which makes this worth memorising as a closed set of three.
Question 5
A user wants to convert numeric field values to strings and also to sort on those values. Which command should be used FIRST, the eval or the sort?- A. It doesn't matter whether eval or sort is used first.
- B. Convert the numeric to a string with eval first, then sort.
- C. Use sort first, then convert the numeric to a string with eval.
- D. You cannot use the sort command and the eval command on the same field.
Explanation
The correct answer is: C. Use sort first, then convert the numeric to a string with eval..
The order matters because sort behaves differently depending on the data type of the field it is given. While the values are still numeric, sort orders them numerically, so 9 comes before 10 and 100 comes after 99. Once eval has converted those values to strings, sort switches to lexicographic ordering, where 10 precedes 9 because comparison proceeds character by character from the left. Since the requirement is to sort on the numeric values, the sort must happen while the field is still numeric and the eval conversion must come afterward, and the pipeline preserves the established order through that later eval. Running eval first produces a syntactically valid search that returns the wrong ordering, which is why this is a correctness issue rather than a matter of style. The claim that order does not matter ignores this type-driven behavior, and nothing prevents sort and eval from operating on the same field.
Other Splunk Core Certified Power User domains
- Correlating Events (24 questions)
- Creating and Managing Fields (21 questions)
- Creating and Using Macros (20 questions)
- Creating and Using Workflow Actions (25 questions)
- Creating Data Models (27 questions)
- Creating Field Aliases and Calculated Fields (22 questions)
- Creating Tags and Event Types (21 questions)
- Using the Common Information Model (CIM) (17 questions)
- Using Transforming Commands for Visualizations (19 questions)