Splunk Core Certified User Preparation Details
The Splunk Core Certified User (SPLK-1001) exam validates entry-level skills in navigating Splunk Web, running basic searches, and building simple reports, dashboards, and alerts. This guide maps every topic in the official test blueprint to current Splunk documentation so you can study each skill in order. You can also explore more Splunk certification study guides on the Splunk category to keep building your skills.
Splunk Core Certified User Materials
| Coursera | Splunk Core Certified User (SPLK-1001) Prep Guide |
| Udemy | Splunk Core Certified User Course – SPLK-1001 |
| Whizlabs | Splunk Core Certified User |
1.0 Splunk Basics 5%
1.1 Splunk components
Components of a Splunk Enterprise deployment
1.2 Understand the uses of Splunk
1.3 Define Splunk apps
Managing app and add-on configurations and properties
1.4 Customizing user settings
1.5 Basic navigation in Splunk
2.0 Basic Searching 22%
2.1 Run basic searches
Basic searches and search results
2.2 Set the time range of a search
Select time ranges to apply to your search
2.3 Identify the contents of search results
Basic searches and search results
2.4 Refine searches
Basic searches and search results
2.5 Use the timeline
Use the timeline to investigate events
2.6 Work with events
Basic searches and search results
2.7 Control a search job
2.8 Save search results
3.0 Using Fields in Searches 20%
3.1 Understand fields
3.2 Use fields in searches
3.3 Use the fields sidebar
4.0 Search Language Fundamentals 15%
4.1 Review basic search commands and general search practices
4.2 Examine the search pipeline
4.3 Specify indexes in searches
4.4 Use the following commands to perform searches: tables, rename, fields, dedup, and sort
5.0 Using Basic Transforming Commands 15%
5.1 The top command
5.2 The rare command
5.3 The stats command
6.0 Creating Reports and Dashboards 12%
6.1 Save a search as a report
6.2 Edit reports
6.3 Create reports that display statistics (tables)
6.4 Create reports that display visualizations (charts)
6.5 Create a dashboard
6.6 Add a report to a dashboard
Use reports and saved searches with ds.savedSearch
6.7 Edit a dashboard
7.0 Creating and Using Lookups 6%
7.1 Describe lookups
7.2 Examine a lookup file example
Define a CSV lookup in Splunk Web
7.3 Create a lookup file and create a lookup definition
Define a CSV lookup in Splunk Web
7.4 Configure an automatic lookup
Define an automatic lookup in Splunk Web
7.5 Use the lookup in searches
8.0 Creating Scheduled Reports and Alerts 5%
8.1 Describe scheduled reports
8.2 Configure scheduled reports
8.3 Describe alerts
8.4 Create alerts
8.5 View fired alerts
Wrapping Up Splunk Core Certified User
This guide walked through every domain of the SPLK-1001 blueprint, from Splunk basics and searching through fields, reports, dashboards, lookups, and scheduled alerts. Working through each linked doc alongside the tutorial data will build the hands-on comfort the Splunk Core Certified User exam expects. You can also explore more Splunk certification study guides on the Splunk category to keep building your skills. Have a question or tip? Leave a comment below.
Receive Updates on Splunk Core Certified User Exam
Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.