SPLK-4001 — Splunk O11y Cloud Certified Metrics User
Splunk

Splunk O11y Cloud Certified Metrics User (SPLK-4001) Practice Questions

★★★★★★ 4.4 138 verified reviews
125 questions
June 17, 2026 updated
✓ Online quiz simulator

Domain coverage

  • Metrics Concepts (15%)
  • OpenTelemetry & Data Ingest (15%)
  • Navigating & Searching Metrics (10%)
  • Dashboards & Visualization (15%)
  • Finding Insights Using Analytics (15%)
  • Alerting on Metrics with Detectors (15%)
  • Muting Alerts & Maintenance (8%)
  • Teams & Permissions (7%)

Sample Questions (13 of 125 shown)

Q1 Get Metrics In with OpenTelemetry (10%)
In the Splunk distribution of the OpenTelemetry Collector, what is the difference between agent_config.yaml and splunk-otel-collector.conf?
  1. splunk-otel-collector.conf defines the OpenTelemetry pipelines, while agent_config.yaml sets endpoint URLs and access tokens
  2. splunk-otel-collector.conf configures processors, while agent_config.yaml sets the collector's memory limits
  3. agent_config.yaml configures gateway addresses, while splunk-otel-collector.conf sets the collector's memory limits
  4. agent_config.yaml defines the OpenTelemetry pipelines, while splunk-otel-collector.conf sets endpoint URLs and access tokens
✓ Correct Answer: A
In the Splunk distribution of the OpenTelemetry Collector, splunk-otel-collector.conf defines the OpenTelemetry pipelines (receivers, processors, exporters), while agent_config.yaml is used to configure environment-specific settings such as endpoint URLs, access tokens, and other deployment-specific configurations.
Q2 Get Metrics In with OpenTelemetry (10%)
Which component of the OpenTelemetry Collector allows modification of metadata?
  1. Processors
  2. Pipelines
  3. Exporters
  4. Receivers
✓ Correct Answer: A
Processors in the OpenTelemetry Collector are components that can modify telemetry data before it is sent to exporters. They can perform transformations such as filtering, adding, deleting, or updating attributes, tags, or resources. The attributes processor and resource processor are specifically designed for metadata modification.
Q3 Get Metrics In with OpenTelemetry (10%)
A collector configuration was edited to add a hostmetrics receiver, but no host metrics are exported. Which configuration issue is most likely?
  1. The receiver was defined but not referenced in a metrics pipeline that uses the Splunk exporter
  2. The dashboard group was not renamed after the receiver was added
  3. The user forgot to create a muting rule before starting the collector
  4. The metric chart was not converted to a pie chart
✓ Correct Answer: A
In the OpenTelemetry Collector, simply defining a receiver is not sufficient. The receiver must be referenced in a metrics pipeline within the service section of the configuration. The pipeline connects receivers, processors, and exporters, specifying the data flow path. Without the pipeline reference, the receiver is defined but never activated.
Q4 Get Metrics In with OpenTelemetry (10%)
Deploy the OTel Collector on Linux. Which command is used to install the Splunk Distribution of the OpenTelemetry Collector on Linux?
  1. sudo apt-get install splunk-otel-collector
  2. curl -sSL https://dl.signalfx.com/splunk-otel-collector.sh | sh
  3. docker run splunk/otel-collector
  4. pip install splunk-otel-collector
✓ Correct Answer: B
The Splunk Distribution of the OpenTelemetry Collector is installed on Linux using the installation script from dl.signalfx.com. The script downloads and configures the collector with the appropriate settings for the environment, including the realm and access token.
Q5 Get Metrics In with OpenTelemetry (10%)
Configure the OTel Collector. Which file is the primary configuration file for the Splunk Distribution of the OpenTelemetry Collector on Linux?
  1. /etc/otel/collector/config.yaml
  2. /etc/otel/collector/agent_config.yaml
  3. /opt/splunk-otel-collector/agent_config.yaml
  4. $SPLUNK_HOME/etc/otel-collector.conf
✓ Correct Answer: C
The primary configuration file for the Splunk Distribution of the OpenTelemetry Collector on Linux is located at /etc/otel/collector/agent_config.yaml (or /opt/splunk-otel-collector/agent_config.yaml depending on installation). This file defines the collector's receivers, processors, exporters, and service pipelines.
Q6 Get Metrics In with OpenTelemetry (10%)
Edit the configuration. When modifying the OTel Collector configuration to add a new receiver, where must the receiver be added to become active?
  1. Only in the receivers section
  2. In both the receivers section and a pipeline in the service section
  3. Only in the exporters section
  4. In the extensions section
✓ Correct Answer: B
To add a new receiver to the OpenTelemetry Collector, it must first be defined in the receivers section of the configuration, and then it must be added to a metrics (or traces/logs) pipeline in the service section. The pipeline definition connects the receiver to the appropriate processors and exporters.
Q7 Get Metrics In with OpenTelemetry (10%)
Troubleshooting common errors. Which log can be checked to troubleshoot OpenTelemetry Collector issues?
  1. /var/log/splunk/otel-collector.log
  2. /var/log/messages
  3. Journalctl logs for the splunk-otel-collector service
  4. /opt/splunk-otel-collector/logs/collector.log
✓ Correct Answer: C
On Linux systems where the Splunk Distribution of the OpenTelemetry Collector is installed as a systemd service, the primary source for troubleshooting is the journalctl logs: journalctl -u splunk-otel-collector. These logs contain collector output, errors, and warnings about configuration issues, connection problems, and data processing.
Q8 Get Metrics In with OpenTelemetry (10%)
General OpenTelemetry Concepts. What is OpenTelemetry?
  1. A proprietary observability framework owned by Splunk
  2. An open-source observability framework for collecting, processing, and exporting telemetry data (metrics, traces, and logs)
  3. A commercial APM solution
  4. A database for storing time-series data
✓ Correct Answer: B
OpenTelemetry (OTel) is an open-source observability framework under the Cloud Native Computing Foundation (CNCF). It provides APIs, SDKs, and tools for generating, collecting, processing, and exporting telemetry data including metrics, traces, and logs. It is vendor-agnostic and supported by Splunk and many other observability platforms.
Q9 Get Metrics In with OpenTelemetry (10%)
What are the three main types of signals defined in the OpenTelemetry specification?
  1. Metrics, Traces, Logs
  2. Events, Metrics, Traces
  3. Logs, Events, Alerts
  4. Metrics, Alerts, Dashboards
✓ Correct Answer: A
The OpenTelemetry specification defines three primary signal types: Metrics (measurements about system performance), Traces (records of the execution path of requests through distributed systems), and Logs (timestamped text records of events). Together they provide comprehensive observability.
Q10 Get Metrics In with OpenTelemetry (10%)
What is the role of the OTel Collector gateway mode?
  1. To collect data from a single host and send directly to the backend
  2. To act as a centralized intermediary that receives data from multiple agent collectors, processes it, and forwards it to the backend
  3. To replace the need for any agents on individual hosts
  4. To store metrics locally for historical analysis
✓ Correct Answer: B
In gateway mode, the OpenTelemetry Collector acts as a centralized intermediary (gateway) that receives telemetry data from multiple agent collectors deployed on individual hosts. It can perform centralized processing, filtering, and batching before forwarding data to the Splunk Observability Cloud backend.
Q11 Get Metrics In with OpenTelemetry (10%)
What is the role of the OTel Collector agent mode?
  1. To collect data from a single host and send it directly to the backend or to a gateway collector
  2. To act as a centralized data processing hub
  3. To replace existing monitoring agents entirely
  4. To store telemetry data for compliance purposes
✓ Correct Answer: A
In agent mode, the OpenTelemetry Collector runs on each individual host and collects telemetry data locally. It sends the data directly to the Splunk Observability Cloud backend or to a gateway collector for centralized processing. Agent mode is the most common deployment pattern.
Q12 Get Metrics In with OpenTelemetry (10%)
Which receiver in the OpenTelemetry Collector is used to collect host-level metrics such as CPU, memory, and disk usage?
  1. hostmetrics receiver
  2. kubeletstats receiver
  3. prometheus receiver
  4. filelog receiver
✓ Correct Answer: A
The hostmetrics receiver in the OpenTelemetry Collector is specifically designed to collect host-level metrics including CPU utilization, memory usage, disk I/O, network traffic, and filesystem usage. It is one of the most commonly used receivers for infrastructure monitoring.
Q13 Get Metrics In with OpenTelemetry (10%)
What is required to authenticate the OpenTelemetry Collector with Splunk Observability Cloud?
  1. A username and password
  2. An API access token
  3. An SSL certificate
  4. A Splunk license key
✓ Correct Answer: B
The OpenTelemetry Collector authenticates with Splunk Observability Cloud using an API access token (also called a SignalFx access token). This token is configured in the exporter settings within the collector configuration and identifies the organization account that the data should be sent to.

You've viewed 3 of 125 questions. Start the free practice exam to answer all questions with instant feedback.

Exam overview

Tailored for DevOps engineers and SREs managing real-time metric streams, the Splunk O11y Cloud Certified Metrics User (SPLK-4001) certification validates your ability to navigate Splunk Observability Cloud, configure OpenTelemetry pipelines, and build metric-based detectors. Administered through Pearson VUE, this 60-minute exam requires a scaled passing score of 700/1000 and has no formal prerequisite certifications, though a foundational understanding of cloud metrics infrastructure and microservices architecture is recommended.

Splunk recommends completing the Splunk Observability Cloud Foundations and Visualizing and Alerting on Metrics in Splunk Observability Cloud training courses, paired with at least 3 to 6 months of hands-on experience using Splunk Observability Cloud (SignalFx components) within a DevOps, continuous delivery, or SRE ecosystem.

Unlike traditional Splunk core exams that focus on SPL index searches and data storage buckets, the SPLK-4001 blueprint is organized around 8 domains centered on real-time metric streams. The highest weighted areas — Metrics Concepts (15%), OpenTelemetry & Data Ingest (15%), Dashboards & Visualization (15%), Finding Insights Using Analytics (15%), and Alerting on Metrics with Detectors (15%) — demand competency in Metric Time Series (MTS) architecture, OTel Collector pipeline configuration (receivers, processors, exporters), analytics with Top/Bottom N and timeshift modifiers, and detector threshold tuning with trigger sensitivity parameters.

For candidates preparing for the SPLK-4001 exam, our practice materials cover all 8 domains in the same proportions as the real test — from Metrics Concepts differentiating metrics/logs/traces with MTS architecture and data resolution rollup behaviors through OpenTelemetry & Data Ingest with OTel Collector components (receivers, processors, exporters) and data ingestion ports (gRPC 4317, SignalFx 9080), Navigating & Searching Metrics using key-value filter syntax and Metadata Catalog tools, Dashboards & Visualization with chart layout configurations and MTS plot limit handling, Finding Insights Using Analytics with mathematical formulas, percentages, ratios, timeshift, and Top/Bottom N modifiers for high-cardinality dimensions, Alerting on Metrics with Detectors creating custom alert rules, static thresholds, and trigger sensitivity parameters (duration, windows), Muting Alerts & Maintenance with precise structural target scopes and automated maintenance windows, and Teams & Permissions managing multi-tenant visibility with role-based dashboard and alert assignments. Each online practice question includes a detailed answer explanation that walks through the Observability Cloud reasoning, while the downloadable PDF packages the same question bank for offline review during commutes or in environments without stable internet.

Start your free SPLK-4001 practice test today and master Splunk Observability Cloud metric monitoring, OTel pipelines, and alert detectors.

Official Exam Domains & Weighting

To successfully pass the SPLK-4001 exam, candidates must master the following core domains:
  • Domain 1: Metrics Concepts (15%) — Differentiating metrics, logs, and traces; understanding Metric Time Series (MTS) architecture; analyzing metadata, dimensions, and properties; and understanding data resolution and rollup behaviors.
  • Domain 2: OpenTelemetry & Data Ingest (15%) — Describing OTel Collector components (receivers, processors, exporters); configuring basic metrics pipeline components; tracking data ingestion ports (gRPC 4317, SignalFx 9080); and troubleshooting data-dropping errors.
Domain 3: Navigating & Searching Metrics (10%) — Filtering and isolating metrics using key-value syntax with wildcards (e.g., host:test-), utilizing Metadata Catalog tools, and analyzing metrics streams globally.
  • Domain 4: Dashboards & Visualization (15%) — Building and maintaining charts in dashboards, managing chart layout configurations, and handling MTS plot limit constraints.
  • Domain 5: Finding Insights Using Analytics (15%) — Applying functions and mathematical formulas (percentages, ratios, timeshift, Top/Bottom N modifiers) and handling high-cardinality dimension combinations.
  • Domain 6: Alerting on Metrics with Detectors (15%) — Creating custom alert rules via detectors, implementing static thresholds, and configuring trigger sensitivity parameters (duration, windows) to suppress environmental jitter.
  • Domain 7: Muting Alerts & Maintenance (8%) — Formulating muting rules based on precise structural target scopes and establishing automated maintenance windows to silence alerts during deployments.
  • Domain 8: Teams & Permissions (7%) — Managing multi-tenant visibility controls, establishing separate Teams within Splunk Observability Cloud, and assigning role permissions to dashboards and alerts.

What Our Customers Say 138 verified reviews

4.4 ★★★★★★ Based on 138 reviews
★★★★★
I bought the SPLK-4001 question bank a week before my exam and passed with 90%+. The questions are that good.
— Maria V.
★★★★★★
My boss asked me to get the SPLK-4001 cert for work. This was the best study tool I found. Passed in three weeks.
— Austin P.
★★★★★
Ended up buying three different SPLK-4001 prep resources and this was by far the most helpful one. Don’t waste money on others.
— Penelope W.
★★★★★★
Great Splunk exam preparation tool. The SPLK-4001 questions are current and the interface is clean and easy to use.
— Chris D.
★★★★★
Passed SPLK-4001 with 94%. If you’re serious about this certification, get this question bank and thank me later.
— Hunter P.
★★★★★★
Worth every cent for the SPLK-4001 certification prep. Detailed answers helped me understand concepts I was shaky on.
— Zachary M.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

While core Splunk certifications focus on SPL index searches and data storage, SPLK-4001 tests your competency in real-time metric streams, microservice analytics, and the OpenTelemetry (OTel) standard. It is oriented toward DevOps, Cloud Architects, and SREs rather than centralized log management admins.

Handling Metric Time Series (MTS) plot limitations is a frequent challenge. When running analytics across environments with tens of thousands of active hosts, a single plot may hit its structural limit — the exam tests your ability to apply specific filters to lower metrics scope without breaking charts. Our practice materials include MTS limit scenarios.

A mandatory 7-day cooldown before retaking, with the full $130 fee required each attempt.

Three years from the pass date.

Our mock exam covers all 8 domains with the same weight distribution as the real test — from MTS architecture with metrics/logs/traces differentiation through OTel Collector pipeline configuration (receivers, processors, exporters) and gRPC 4317/SignalFx 9080 port tracking, Metadata Catalog metric filtering with wildcard syntax, dashboard chart layout and MTS plot limit handling, analytics with Top/Bottom N modifiers and timeshift for high-cardinality data, detector creation with static thresholds and trigger sensitivity windows, muting rules with structural target scopes, and team-based permission management. Each question includes Observability Cloud specific reasoning.

Yes. The downloadable PDF contains the same question bank as the online version, including answer explanations covering MTS data resolution and rollup behaviors, OTel Collector pipeline troubleshooting, Metadata Catalog search patterns, chart plot limit workarounds, analytics formula and modifier applications, detector threshold configuration and jitter suppression, muting rule scope design, and multi-tenant team permission structures. It is designed for offline study.

Candidates report OpenTelemetry & Data Ingest (15%) as the most technically demanding, especially OTel Collector pipeline troubleshooting and port configuration. Finding Insights Using Analytics (15%) with high-cardinality dimension handling and Alerting on Metrics with Detectors (15%) with trigger sensitivity parameter tuning are also frequently cited. Our practice questions include focused drills on these areas.