Which Default Splunk Role Can Use the Log Event Alert Action?

What default Splunk role can use the Log Event alert action?

  1. Power Source Reference Answer
  2. User
  3. can_delete
  4. Admin

Community Votes

A
50%
D
25%
C
25%

50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your knowledge of default role capabilities and the edit_tcp requirement for Log Event alerts, with a common trap being to assume Admin is required simply because it has all capabilities.

The Log Event alert action in Splunk requires the edit_tcp capability, which is included in the default Power role. Community consensus and official docs indicate that Power, not Admin or User, is the intended correct answer in the SPLK-1004 exam context.

Choosing Admin is the most common mistake because Admin has all capabilities, but the Power role is the default role that is specifically designed to use the Log Event alert action; Admin is typically needed only to edit or modify the action, not to use it.

Community Discussion (6 comments)

Soccerfan 👍 2
A - https://docs.splunk.com/Documentation/Splunk/9.3.1/Security/Rolesandcapabilities
AnE_splunk 👍 1
Using the log event alert action requires the edit_tcp capability for users without the admin role.
jaemon22 👍 2 Selected: A
Correction answer is A, the answer C i provided earlier was for anoher question.
jaemon22 👍 1 Selected: C
It's C
Eddie_exam 👍 1 Selected: D
Correct answer is the Admin user. Power user needs the edit_tcp capability. See Fundamentals 3 slide 108.
Derag 👍 1
A power user with edit_tcp capability can use the log event. The Admin role is required to edit/modify it.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The Log Event alert action requires the edit_tcp capability. Among Splunk's default roles, the Power role includes edit_tcp, so it can use this alert action without additional configuration. Commenters supporting option A correctly referenced the Splunk Security Roles and Capabilities documentation and explained that a Power user with edit_tcp can use the log event. The suggested answer is A (Power).

Why the Other Options Are Wrong

User (B) lacks the edit_tcp capability and therefore cannot use the Log Event action. can_delete (C) is a special-purpose role focused on deletion capabilities and does not include alert action permissions. Admin (D) technically also has edit_tcp, but the exam question asks which default role can use the action, and the Power role is the standard answer in Splunk training materials. Some commenters confused the ability to use with the ability to modify, which led to the Admin answer.

Community Comment Notes

Several comments point to the official Splunk documentation for roles and capabilities. One comment correctly identifies that edit_tcp is required for non-admin users. Another clarifies that a Power user with edit_tcp can use the Log Event action, while the Admin role is needed to edit/modify it. Commenters choosing Admin or can_delete did not provide authoritative documentation backing, making the Power answer the most defensible.

Official Reference

Exam Strategy

When answering role-based questions on the SPLK-1004 exam, focus on the specific capability required by the action, not just the most powerful role. Remember that default roles like Power include specific capabilities such as edit_tcp, while Admin is often needed only for modifying or configuring, not for using the feature.

Related Analysis

Practice All SPLK-1004 Questions

Access 130 questions with complete answers and detailed explanations.

View Full SPLK-1004 Practice Test →

← Back to SPLK-1004 Study Guide