Splunk Core Certified User Exam Study Guide (SPLK-1001)

Splunk-Core-Certified-User

Splunk Core Certified User Preparation Details

The Splunk Core Certified User (SPLK-1001) exam validates entry-level skills in navigating Splunk Web, running basic searches, and building simple reports, dashboards, and alerts. This guide maps every topic in the official test blueprint to current Splunk documentation so you can study each skill in order. You can also explore more Splunk certification study guides on the Splunk category to keep building your skills.

Splunk Core Certified User Materials

CourseraSplunk Core Certified User (SPLK-1001) Prep Guide
UdemySplunk Core Certified User Course – SPLK-1001
WhizlabsSplunk Core Certified User

1.0 Splunk Basics 5%

1.1 Splunk components

Components of a Splunk Enterprise deployment

About Splunk Enterprise

1.2 Understand the uses of Splunk

About Splunk Enterprise

Get started with Search

1.3 Define Splunk apps

Review your apps and add-ons

Managing app and add-on configurations and properties

1.4 Customizing user settings

Navigating Splunk Web

1.5 Basic navigation in Splunk

Navigating Splunk Web

Get started with Search

2.0 Basic Searching 22%

2.1 Run basic searches

Get started with Search

Basic searches and search results

2.2 Set the time range of a search

Select time ranges to apply to your search

Specifying time ranges

2.3 Identify the contents of search results

Basic searches and search results

Use fields to search

2.4 Refine searches

Basic searches and search results

Quick tips for optimization

2.5 Use the timeline

Use the timeline to investigate events

2.6 Work with events

Basic searches and search results

2.7 Control a search job

About jobs and job management

2.8 Save search results

Export search results

Create and edit reports

3.0 Using Fields in Searches 20%

3.1 Understand fields

About fields

Use default fields

3.2 Use fields in searches

Use fields to search

3.3 Use the fields sidebar

Use fields to search

4.0 Search Language Fundamentals 15%

4.1 Review basic search commands and general search practices

Command quick reference

Quick tips for optimization

4.2 Examine the search pipeline

Anatomy of a search

4.3 Specify indexes in searches

Retrieve events from indexes

4.4 Use the following commands to perform searches: tables, rename, fields, dedup, and sort

table

rename

fields

dedup

sort

5.0 Using Basic Transforming Commands 15%

5.1 The top command

top

5.2 The rare command

rare

5.3 The stats command

stats

Command quick reference

6.0 Creating Reports and Dashboards 12%

6.1 Save a search as a report

Create and edit reports

6.2 Edit reports

Create and edit reports

6.3 Create reports that display statistics (tables)

Create dashboards and panels

Create and edit reports

6.4 Create reports that display visualizations (charts)

Create dashboards and panels

6.5 Create a dashboard

Create dashboards and panels

6.6 Add a report to a dashboard

Use reports and saved searches with ds.savedSearch

6.7 Edit a dashboard

Create dashboards and panels

7.0 Creating and Using Lookups 6%

7.1 Describe lookups

About lookups

7.2 Examine a lookup file example

Define a CSV lookup in Splunk Web

Configure CSV lookups

7.3 Create a lookup file and create a lookup definition

Define a CSV lookup in Splunk Web

Configure CSV lookups

7.4 Configure an automatic lookup

Define an automatic lookup in Splunk Web

7.5 Use the lookup in searches

lookup

8.0 Creating Scheduled Reports and Alerts 5%

8.1 Describe scheduled reports

Schedule reports

Getting started with alerts

8.2 Configure scheduled reports

Schedule reports

8.3 Describe alerts

Getting started with alerts

8.4 Create alerts

Create scheduled alerts

Create real-time alerts

Alert scheduling tips

8.5 View fired alerts

Monitor triggered alerts

Triggered alerts

Wrapping Up Splunk Core Certified User

This guide walked through every domain of the SPLK-1001 blueprint, from Splunk basics and searching through fields, reports, dashboards, lookups, and scheduled alerts. Working through each linked doc alongside the tutorial data will build the hands-on comfort the Splunk Core Certified User exam expects. You can also explore more Splunk certification study guides on the Splunk category to keep building your skills. Have a question or tip? Leave a comment below.

Receive Updates on Splunk Core Certified User Exam


Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.

Share the Splunk Core Certified User Study Guide in Your Network

You may also like

Leave a Reply

Your email address will not be published. Required fields are marked *