Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
SPLUNK

Splunk Core Certified Advanced Power User

core-certified-advanced-power-userSplunk Advanced Power User

The Splunk Core Certified Advanced Power User certification validates your ability to author complex searches and reports, implement advanced knowledge object use cases, and apply best practices for building dashboards and forms. It is designed for power users who want to deepen their expertise and get more value from their Splunk Enterprise or Splunk Cloud deployment. Earning this credential demonstrates you can turn raw data into actionable insights and sets you on a path toward advanced Splunk roles.

439 practice questions · Updated 2025-01-01

5Domains
26Objectives
159Concepts
439Questions

core-certified-advanced-power-user Curriculum

Every domain, objective, and concept the core-certified-advanced-power-user exam measures.

Statistical and Transforming Commands

8 concepts · 20 questions
  1. stats function
  2. fieldsummary
  3. appendpipe
  4. count and list functions
  5. eventstats
  6. streamstats
  7. statistical functions
  8. makeresults command

String and Conditional Functions

5 concepts · 16 questions
  1. Conversion functions
  2. Text functions
  3. Comparison functions
  4. Conditional functions
  5. Informational functions

Transactions

7 concepts · 10 questions
  1. Transaction Definition
  2. Transaction Evaluation
  3. Handling Common Values
  4. Coalesce Alternative
  5. Complete vs Incomplete Transactions
  6. Transaction Efficiency
  7. Stats vs Transactions

Subsearches

12 concepts · 29 questions
  1. Subsearch basics
  2. Filtering with subsearches
  3. Subsearch result limits
  4. Subsearch time range behavior
  5. Subsearch output fields
  6. When to use subsearch
  7. When NOT to use subsearch
  8. Subsearch performance caveats
  9. Subsearch syntax and formatting caveats
  10. Troubleshooting subsearch results
  11. Troubleshooting subsearch errors
  12. Subsearch debugging techniques

Append and Time Management

3 concepts · 10 questions
  1. append command
  2. Using time effectively
  3. Default time fields

Lookups

7 concepts · 14 questions
  1. Advanced lookup options
  2. Including events based on lookup values
  3. Excluding events based on lookup values
  4. KV Store lookups
  5. External lookups
  6. Geospatial lookups
  7. Lookup best practices

Field Extractions

5 concepts · 17 questions
  1. Identify field extraction methods
  2. Use the Field Extractor to create a regex extraction
  3. Perform search-time extraction with rex
  4. Perform search-time extraction with erex
  5. Optimize regex performance in Splunk

Self-Describing Data

6 concepts · 10 questions
  1. Definition of self-describing data
  2. spath command basics
  3. spath with field extraction
  4. eval with spath function
  5. multikv command basics
  6. multikv with custom settings

Data Transformations

5 concepts · 14 questions
  1. bin command
  2. xyseries command
  3. untable command
  4. foreach command
  5. strftime function

Multivalued Fields

6 concepts · 20 questions
  1. Multivalued fields
  2. Creating multivalued fields
  3. makemv command
  4. mvexpand command
  5. Multivalued eval functions
  6. Using multivalued fields in searches

  1. Logging searchable alert events
  2. Configuring alert logging
  3. Searching alert events
  4. Indexing alert events

Referencing lookups in alerts

4 concepts · 10 questions
  1. Lookup Definition in Alerts
  2. Alert Action Lookup Syntax
  3. Passing Alert Results to Lookup
  4. Handling Lookup Errors in Alerts

Outputting alert results to a lookup

5 concepts · 15 questions
  1. Alert actions overview
  2. Configuring lookup output in alerts
  3. Lookup file requirements
  4. Handling lookup output modes
  5. Verifying alert output to lookup

Using a webhook alert action

4 concepts · 21 questions
  1. Webhook alert action overview
  2. Configuring a webhook alert action
  3. Customizing webhook payloads
  4. Testing and troubleshooting webhook alerts

Creating a log event alert action

4 concepts · 20 questions
  1. Log event alert action overview
  2. Configuring a log event alert action
  3. Understanding log event alert action limitations
  4. Testing and validating log event alert actions

Using nested search macros

5 concepts · 9 questions
  1. Nested macro syntax
  2. Macro argument passing
  3. Macro expansion order
  4. Debugging nested macros
  5. Recursive macro usage
  1. Purpose of macro preview
  2. Previewing a macro in the search bar
  3. Previewing a macro in the macro editor
  4. Interpreting preview results
  1. Macro Definition and Usage
  2. Macro Arguments and Parameters
  3. Using Macros with Lookups
  4. Using Macros with Field Extractions
  5. Using Macros with Saved Searches and Alerts
  6. Using Macros with Data Models
  7. Using Macros with Subsearches
  8. Using Macros with Event Types and Tags
  9. Using Macros with Workflow Actions
  10. Using Macros with Other Macros
  11. Macro Scope and Permissions
  12. Macro Expansion and Debugging

Understanding Acceleration

11 concepts · 29 questions
  1. Definition of acceleration
  2. Eligibility criteria for report acceleration
  3. Conditions preventing summary creation
  4. Steps to accelerate a report
  5. Report Acceleration Summaries page
  6. Summary Detail page
  7. Concept of summary indexing
  8. Summary indexing transforming commands
  9. Searching against a summary index
  10. Handling gaps in summary indexes
  11. Handling overlaps in summary indexes

Data Model Acceleration

8 concepts · 26 questions
  1. datamodel command basics
  2. data model acceleration overview
  3. accelerating a data model
  4. tsidx file structure
  5. tsidx file lifecycle
  6. tstats command fundamentals
  7. tstats with accelerated data models
  8. choosing acceleration options

Search Performance Fundamentals

7 concepts · 18 questions
  1. Splunk architecture components
  2. Search flow
  3. Streaming commands
  4. Transforming commands
  5. Command ordering
  6. Job inspector
  7. Pre-Filtering search data

Search Optimization Techniques

7 concepts · 8 questions
  1. Lispy and boolean operators
  2. Lispy and wildcards
  3. Using the TERM directive
  4. Improving dashboard performance
  5. Using the tstats command
  6. Creating base searches
  7. Creating post-process searches

Creating and Troubleshooting Views

4 concepts · 20 questions
  1. Simple XML syntax for views
  2. View creation best practices
  3. Troubleshooting views
  4. Simple XML extensions

Using Tokens

5 concepts · 15 questions
  1. Token fundamentals
  2. Tokens with form inputs
  3. Cascading inputs
  4. Token filters
  5. Predefined tokens

Customizing Dashboards

6 concepts · 18 questions
  1. Chart property customization
  2. Panel property customization
  3. Setting panel refresh intervals
  4. Setting panel delay times
  5. Disabling search access features
  6. Creating event annotations
  1. Types of Drilldowns
  2. Dynamic Drilldowns
  3. Event Handler Types
  4. Event Actions
  5. Contextual Drilldowns
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for core-certified-advanced-power-user, so none is invented.