Splunk Core Certified Advanced Power User Study Guide (SPLK-1004)

Splunk-Core-Certified-Advanced-Power-User

Splunk Core Certified Advanced Power User Preparation Details

The Splunk Core Certified Advanced Power User exam (SPLK-1004) validates advanced SPL skills across statistical commands, lookups, alerting, field extraction, data models, and dashboard customization. This guide maps every objective from the official test blueprint to the current Splunk documentation so you can study each topic methodically. It builds directly on the Power User certification and is aimed at candidates ready to master complex searches, transactions, and interactive dashboards. You can also explore more Splunk certification study guides on the Splunk Certification category to keep building your skills.

Splunk Core Certified Advanced Power User Materials

CourseraSplunk Query Language and Data Analysis
UdemySplunk Core Certified Advanced Power User PreExam
WhizlabsSplunk Basics

1.0 Exploring Statistical Commands 4%

1.1 Performing statistical analysis with stats function

stats

Aggregate functions

Evaluation functions

1.2 Using fieldsummary

fieldsummary

Command types

1.3 Using appendpipe

appendpipe

append

1.4 Using count and list functions

Aggregate functions

Multivalue stats and chart functions

1.5 Using eventstats

eventstats

stats

1.6 Using streamstats

streamstats

eventstats

2.0 Exploring eval Command Functions 4%

2.1 Using conversion functions

Conversion functions

Evaluation functions

2.2 Using text functions

Text functions

2.3 Using comparison and conditional functions

Comparison and Conditional functions

2.4 Using informational functions

Informational functions

2.5 Using statistical functions

Statistical eval functions

2.6 Using makeresults command

makeresults

3.0 Exploring Lookups 4%

3.1 Applying advanced lookup options

About lookups

Configure a time-based lookup

3.2 Including and excluding events based on lookup values

lookup

inputlookup

3.3 Using KV Store lookups

Configure KV Store lookups

outputlookup

3.4 Using external lookups

Configure external lookups

3.5 Using geospatial lookups

Configure geospatial lookups

3.6 Understanding best practices for lookups

About lookups

Lookup example in Splunk Web

4.0 Exploring Alerts 4%

4.1 Logging and indexing searchable alert events

Set up alert actions

Create a log event alert action

4.2 Referencing lookups in alerts

About lookups

Set up alert actions

4.3 Outputting alert results to a lookup

outputlookup

4.4 Using a webhook alert action

Use a webhook alert action

4.5 Creating a log event alert action

Create a log event alert action

5.0 Advanced Field Creation and Management 4%

5.1 Identifying field extraction methods

About field extractions

Manage field extractions

5.2 Providing a regex expression to the Field Extractor to extract a field

Build field extractions with the field extractor

5.3 Performing search time field extraction using the erex and rex commands

erex

rex

5.4 Understand how to improve regex performance in Splunk

Improve the performance of your regular expressions

6.0 Working with Self-Describing Data and Files 3%

6.1 Understanding self-describing data

Extract fields with search commands

6.2 Using the spath command

spath

6.3 Using the eval command with the spath function

spath

Evaluation functions

6.4 Using the multikv command

multikv

7.0 Advanced Search Macros 3%

7.1 Using nested search macros

Use search macros in searches

7.2 Previewing search macros before executing

Use search macros in searches

Define search macros in Settings

7.3 Using other knowledge objects with macros

Search macro examples

8.0 Using Acceleration Options: Reports and Summary Indexing 4%

8.1 Describing acceleration

Accelerate reports

8.2 Identifying which reports qualify for acceleration

Accelerate reports

8.3 Identifying when Splunk doesn’t build an acceleration summary

Manage report acceleration

8.4 Accelerating a report

Accelerate reports

8.5 Using the Report Acceleration Summaries and Summary Detail pages

Manage report acceleration

8.6 Understanding summary Indexing

Use summary indexing

8.7 Using the summary indexing transforming commands

collect

overlap

8.8 Defining searching against a summary

Use summary indexing

8.9 Understanding how to handle gaps and overlaps in summary indexes

overlap

9.0 Using Acceleration Options: Data Models and tsidx Files 4%

9.1 Exploring data models using the datamodel command

datamodel

9.2 Understanding data model acceleration

About data model acceleration

9.3 Accelerating data models

Accelerate data models

9.4 Understanding tsidx files

Accelerate data models

9.5 Working with tsidx files using tstats commands

tstats

9.6 Using tstats to search accelerated data models

tstats

Accelerate data models

9.7 Determining which acceleration option to use

Accelerate reports

About data model acceleration

10.0 Using Search Efficiently 4%

10.1 Splunk architecture components

Components of a Splunk Enterprise deployment

10.2 Search flow

Understanding SPL syntax

10.3 Streaming commands

Command types

10.4 Transforming commands

Command types

10.5 Command ordering

Speed up searches

10.6 Job inspector

View search job properties with the Job Inspector

11.0 More Search Tuning 3%

11.1 Pre-Filtering search data

About Bloom filters

11.2 Lispy and boolean operators

Quick tips for optimization

11.3 Lispy and wildcards

Use wildcards in searches

11.4 Using the TERM directive

Use CASE() and TERM() to match phrases

Control search execution using directives

12.0 Manipulating and FIltering Data 6%

12.1 bin command

bin

12.2 xyseries command

xyseries

12.3 untable command

untable

12.4 foreach command

foreach

12.5 strftime function

Date and Time functions

13.0 Working with Multivalued Fields 7%

13.1 Multivalued fields

About multivalue fields

13.2 Some multivalued eval functions

Multivalue eval functions

13.3 makemv command

makemv

13.4 mvexpand command

mvexpand

14.0 Using Advanced Transactions 5%

14.1 Evaluating events to create transactions

transaction

14.2 Handling common values/different field names

transaction

14.3 An alternative to coalesce

Conversion functions

14.4 Identifying complete vs. incomplete transactions

transaction

14.5 Making transactions more efficient

Speed up searches

transaction

14.6 stats and transactions

stats

transaction

15.0 Working with Time 2%

15.1 Using time effectively

Time modifiers for search

15.2 What are the default time fields

How timestamp assignment works

16.0 Using Subsearches 6%

16.1 Filtering through many results

About subsearches

16.2 Subsearch caveats

About subsearches

16.3 When to use subsearch

Use subsearches

16.4 When NOT to use subsearch

Use subsearches

16.5 Troubleshooting subsearches

About subsearches

16.6 append command

append

17.0 Creating a Prototype 4%

17.1 Define simple XML syntax for views

Simple XML Reference

Editing Simple XML

17.2 Use best practices for creating views

Simple XML Reference

17.3 Troubleshooting views

Editing Simple XML

18.0 Using Forms 5%

18.1 Explain how tokens work

Token usage in dashboards

18.2 Use tokens with form inputs

Create and edit forms

18.3 Create cascading inputs

Create and edit forms

18.4 Define types of token filters

Token usage in dashboards

19.0 Improving Performance 6%

19.1 Identify ways to improve dashboard performance

Simple XML Reference

Speed up searches

19.2 Use the tstats command

tstats

19.3 Create base and post-process searches

Simple XML Reference

20.0 Customizing Dashboards 6%

20.1 Customize chart and panel properties

Simple XML Reference

20.2 Set panel refresh and delay times

Simple XML Reference

20.3 Disable search access features

Simple XML Reference

20.4 Create event annotations

Simple XML Reference

21.0 Adding Drilldowns 7%

21.1 Define types of drilldowns

Use drilldown for dashboard interactivity

21.2 Identify predefined tokens

Token usage in dashboards

21.3 Create dynamic drilldowns

Use drilldown for dashboard interactivity

22.0 Adding Advanced Behaviors and Visualizations 5%

22.1 Identify types of event handlers

Token usage in dashboards

22.2 Define event actions

Use drilldown for dashboard interactivity

22.3 Create contextual drilldowns

Use drilldown for dashboard interactivity

22.4 Use simple XML extensions

Simple XML Reference

Wrapping Up Splunk Core Certified Advanced Power User

This guide walks through every domain of the Splunk Core Certified Advanced Power User (SPLK-1004) blueprint, from statistical commands and lookups to data model acceleration and dashboard drilldowns. Working through each linked topic in order will help you build the deeper SPL and dashboarding skills the exam expects. You can also explore more Splunk certification study guides on the Splunk Certification category to keep building your skills. Have a question or tip? Leave a comment below.

Receive Updates on Splunk Core Certified Advanced Power User Exam


Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.

Share the Splunk Core Certified Advanced Power User Study Guide in Your Network

You may also like

Leave a Reply

Your email address will not be published. Required fields are marked *