Splunk Core Certified Power User Preparation Details
The Splunk Core Certified Power User (SPLK-1002) exam validates your ability to use transforming commands, correlate events, and build knowledge objects in Splunk. This guide maps every blueprint topic to official Splunk documentation so you can study each domain in order. It covers everything from chart and timechart visualizations to data models and the Common Information Model. You can also explore more Splunk certification study guides on the Splunk category to keep building your skills.
Splunk Core Certified Power User Materials
| Coursera | Splunk Core Certified User (SPLK-1001) Training |
| Udemy | The Complete Splunk Core Certified Power User Course |
1.0 Using Transforming Commands for Visualizations 5%
1.1 Use the chart command
Welcome to the Search Reference
1.2 Use the timechart command
2.0 Filtering and Formatting Results 10%
2.1 The eval command
Use the eval command and functions
2.2 Use the search and where commands to filter results
where command: Overview, syntax, and usage
2.3 The fillnull command
Replacing null values by using the fillnull and filldown commands
3.0 Correlating Events 15%
3.1 Identify transactions
Identify and group events into transactions
3.2 Group events using fields
3.3 Group events using fields and time
Identify and group events into transactions
3.4 Search with transactions
3.5 Report on transactions
3.6 Determine when to use transactions vs. stats
4.0 Creating and Managing Fields 10%
4.1 Perform regex field extractions using the Field Extractor (FX)
Build field extractions with the field extractor
Field Extractor: Select Method step
4.2 Perform delimiter field extractions using the FX
Build field extractions with the field extractor
Field Extractor: Select Method step
5.0 Creating Field Aliases and Calculated Fields 10%
5.1 Describe, create, and use field aliases
Create field aliases in Splunk Web
5.2 Describe, create, and use calculated fields
Create calculated fields with Splunk Web
6.0 Creating Tags and Event Types 10%
6.1 Create and use tags
Tag field-value pairs in Search
6.2 Describe event types and their uses
6.3 Create an event type
Define event types in Splunk Web
7.0 Creating and Using Macros 10%
7.1 Describe macros
7.2 Create and use a basic macro
Define search macros in Settings
7.3 Define arguments and variables for a macro
Define search macros in Settings
7.4 Add and use arguments with a macro
Define search macros in Settings
8.0 Creating and Using Workflow Actions 10%
8.1 Describe the function of GET, POST, and Search workflow actions
About workflow actions in Splunk Web
8.2 Create a GET workflow action
8.3 Create a POST workflow action
8.4 Create a Search workflow action
Set up a search workflow action
9.0 Creating Data Models 10%
9.1 Describe the relationship between data models and pivot
9.2 Identify data model attributes
9.3 Create a data model
10.0 Using the Common Information Model (CIM) Add-On 10%
10.1 Describe the Splunk CIM
Overview of the Splunk Common Information Model
10.2 List the knowledge objects included with the Splunk CIM Add-On
How to use the CIM data model reference tables
10.3 Use the CIM Add-On to normalize data
Use the CIM to normalize data at search time
Wrapping Up Splunk Core Certified Power User
This guide walked through every domain of the Splunk Core Certified Power User (SPLK-1002) blueprint, from transforming commands and event correlation to macros, workflow actions, data models, and the CIM. Working through each objective with official documentation will give you a solid foundation for exam day. You can also explore more Splunk certification study guides on the Splunk category to keep building your skills. Have a question or tip? Leave a comment below.
Receive Updates on Splunk Core Certified Power User Exam
Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.