Splunk Core Certified Power User Exam Study Guide (SPLK-1002)

Splunk-Core-Certified-Power-User

Splunk Core Certified Power User Preparation Details

The Splunk Core Certified Power User (SPLK-1002) exam validates your ability to use transforming commands, correlate events, and build knowledge objects in Splunk. This guide maps every blueprint topic to official Splunk documentation so you can study each domain in order. It covers everything from chart and timechart visualizations to data models and the Common Information Model. You can also explore more Splunk certification study guides on the Splunk category to keep building your skills.

Splunk Core Certified Power User Materials

CourseraSplunk Core Certified User (SPLK-1001) Training
UdemyThe Complete Splunk Core Certified Power User Course

1.0 Using Transforming Commands for Visualizations 5%

1.1 Use the chart command

chart

Welcome to the Search Reference

1.2 Use the timechart command

timechart

timechart command: Usage

2.0 Filtering and Formatting Results 10%

2.1 The eval command

eval

Use the eval command and functions

2.2 Use the search and where commands to filter results

search

where command: Overview, syntax, and usage

2.3 The fillnull command

fillnull

Replacing null values by using the fillnull and filldown commands

3.0 Correlating Events 15%

3.1 Identify transactions

Identify and group events into transactions

About transactions

3.2 Group events using fields

transaction

Search for transactions

3.3 Group events using fields and time

transaction

Identify and group events into transactions

3.4 Search with transactions

Search for transactions

transaction

3.5 Report on transactions

About transactions

stats

3.6 Determine when to use transactions vs. stats

About transactions

stats

4.0 Creating and Managing Fields 10%

4.1 Perform regex field extractions using the Field Extractor (FX)

Build field extractions with the field extractor

Field Extractor: Select Method step

4.2 Perform delimiter field extractions using the FX

Build field extractions with the field extractor

Field Extractor: Select Method step

5.0 Creating Field Aliases and Calculated Fields 10%

5.1 Describe, create, and use field aliases

Create field aliases in Splunk Web

5.2 Describe, create, and use calculated fields

About calculated fields

Create calculated fields with Splunk Web

6.0 Creating Tags and Event Types 10%

6.1 Create and use tags

About tags and aliases

Tag field-value pairs in Search

6.2 Describe event types and their uses

About event types

6.3 Create an event type

Define event types in Splunk Web

7.0 Creating and Using Macros 10%

7.1 Describe macros

Use search macros in searches

7.2 Create and use a basic macro

Define search macros in Settings

7.3 Define arguments and variables for a macro

Define search macros in Settings

7.4 Add and use arguments with a macro

Define search macros in Settings

Use search macros in searches

8.0 Creating and Using Workflow Actions 10%

8.1 Describe the function of GET, POST, and Search workflow actions

About workflow actions in Splunk Web

8.2 Create a GET workflow action

Set up a GET workflow action

8.3 Create a POST workflow action

Set up a POST workflow action

8.4 Create a Search workflow action

Set up a search workflow action

9.0 Creating Data Models 10%

9.1 Describe the relationship between data models and pivot

Introduction to Pivot

About data models

9.2 Identify data model attributes

About data models

9.3 Create a data model

Design data models

10.0 Using the Common Information Model (CIM) Add-On 10%

10.1 Describe the Splunk CIM

Overview of the Splunk Common Information Model

10.2 List the knowledge objects included with the Splunk CIM Add-On

How to use the CIM data model reference tables

10.3 Use the CIM Add-On to normalize data

Use the CIM to normalize data at search time

Wrapping Up Splunk Core Certified Power User

This guide walked through every domain of the Splunk Core Certified Power User (SPLK-1002) blueprint, from transforming commands and event correlation to macros, workflow actions, data models, and the CIM. Working through each objective with official documentation will give you a solid foundation for exam day. You can also explore more Splunk certification study guides on the Splunk category to keep building your skills. Have a question or tip? Leave a comment below.

Receive Updates on Splunk Core Certified Power User Exam


Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.

Share the Splunk Core Certified Power User Study Guide in Your Network

You may also like

Leave a Reply

Your email address will not be published. Required fields are marked *