Which Default Splunk Role Can Use the Log Event Alert Action?
What default Splunk role can use the Log Event alert action?
Community Votes
50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your knowledge of default role capabilities and the edit_tcp requirement for Log Event alerts, with a common trap being to assume Admin is required simply because it has all capabilities.
The Log Event alert action in Splunk requires the edit_tcp capability, which is included in the default Power role. Community consensus and official docs indicate that Power, not Admin or User, is the intended correct answer in the SPLK-1004 exam context.
Choosing Admin is the most common mistake because Admin has all capabilities, but the Power role is the default role that is specifically designed to use the Log Event alert action; Admin is typically needed only to edit or modify the action, not to use it.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The Log Event alert action requires the edit_tcp capability. Among Splunk's default roles, the Power role includes edit_tcp, so it can use this alert action without additional configuration. Commenters supporting option A correctly referenced the Splunk Security Roles and Capabilities documentation and explained that a Power user with edit_tcp can use the log event. The suggested answer is A (Power).
Why the Other Options Are Wrong
User (B) lacks the edit_tcp capability and therefore cannot use the Log Event action. can_delete (C) is a special-purpose role focused on deletion capabilities and does not include alert action permissions. Admin (D) technically also has edit_tcp, but the exam question asks which default role can use the action, and the Power role is the standard answer in Splunk training materials. Some commenters confused the ability to use with the ability to modify, which led to the Admin answer.
Community Comment Notes
Several comments point to the official Splunk documentation for roles and capabilities. One comment correctly identifies that edit_tcp is required for non-admin users. Another clarifies that a Power user with edit_tcp can use the Log Event action, while the Admin role is needed to edit/modify it. Commenters choosing Admin or can_delete did not provide authoritative documentation backing, making the Power answer the most defensible.
Official Reference
Exam Strategy
When answering role-based questions on the SPLK-1004 exam, focus on the specific capability required by the action, not just the most powerful role. Remember that default roles like Power include specific capabilities such as edit_tcp, while Admin is often needed only for modifying or configuring, not for using the feature.
Related Analysis
Practice All SPLK-1004 Questions
Access 130 questions with complete answers and detailed explanations.
View Full SPLK-1004 Practice Test →