
Splunk Core Certified Advanced Power User
The Splunk Core Certified Advanced Power User certification validates your ability to author complex searches and reports, implement advanced knowledge object use cases, and apply best practices for building dashboards and forms. It is designed for power users who want to deepen their expertise and get more value from their Splunk Enterprise or Splunk Cloud deployment. Earning this credential demonstrates you can turn raw data into actionable insights and sets you on a path toward advanced Splunk roles.
439 practice questions · Updated 2025-01-01
core-certified-advanced-power-user Curriculum
Every domain, objective, and concept the core-certified-advanced-power-user exam measures.
- stats function
- fieldsummary
- appendpipe
- count and list functions
- eventstats
- streamstats
- statistical functions
- makeresults command
- Conversion functions
- Text functions
- Comparison functions
- Conditional functions
- Informational functions
- Transaction Definition
- Transaction Evaluation
- Handling Common Values
- Coalesce Alternative
- Complete vs Incomplete Transactions
- Transaction Efficiency
- Stats vs Transactions
- Subsearch basics
- Filtering with subsearches
- Subsearch result limits
- Subsearch time range behavior
- Subsearch output fields
- When to use subsearch
- When NOT to use subsearch
- Subsearch performance caveats
- Subsearch syntax and formatting caveats
- Troubleshooting subsearch results
- Troubleshooting subsearch errors
- Subsearch debugging techniques
- append command
- Using time effectively
- Default time fields
- Advanced lookup options
- Including events based on lookup values
- Excluding events based on lookup values
- KV Store lookups
- External lookups
- Geospatial lookups
- Lookup best practices
- Identify field extraction methods
- Use the Field Extractor to create a regex extraction
- Perform search-time extraction with rex
- Perform search-time extraction with erex
- Optimize regex performance in Splunk
- Definition of self-describing data
- spath command basics
- spath with field extraction
- eval with spath function
- multikv command basics
- multikv with custom settings
- bin command
- xyseries command
- untable command
- foreach command
- strftime function
- Multivalued fields
- Creating multivalued fields
- makemv command
- mvexpand command
- Multivalued eval functions
- Using multivalued fields in searches
- Logging searchable alert events
- Configuring alert logging
- Searching alert events
- Indexing alert events
- Lookup Definition in Alerts
- Alert Action Lookup Syntax
- Passing Alert Results to Lookup
- Handling Lookup Errors in Alerts
- Alert actions overview
- Configuring lookup output in alerts
- Lookup file requirements
- Handling lookup output modes
- Verifying alert output to lookup
- Webhook alert action overview
- Configuring a webhook alert action
- Customizing webhook payloads
- Testing and troubleshooting webhook alerts
- Log event alert action overview
- Configuring a log event alert action
- Understanding log event alert action limitations
- Testing and validating log event alert actions
- Nested macro syntax
- Macro argument passing
- Macro expansion order
- Debugging nested macros
- Recursive macro usage
- Purpose of macro preview
- Previewing a macro in the search bar
- Previewing a macro in the macro editor
- Interpreting preview results
- Macro Definition and Usage
- Macro Arguments and Parameters
- Using Macros with Lookups
- Using Macros with Field Extractions
- Using Macros with Saved Searches and Alerts
- Using Macros with Data Models
- Using Macros with Subsearches
- Using Macros with Event Types and Tags
- Using Macros with Workflow Actions
- Using Macros with Other Macros
- Macro Scope and Permissions
- Macro Expansion and Debugging
- Definition of acceleration
- Eligibility criteria for report acceleration
- Conditions preventing summary creation
- Steps to accelerate a report
- Report Acceleration Summaries page
- Summary Detail page
- Concept of summary indexing
- Summary indexing transforming commands
- Searching against a summary index
- Handling gaps in summary indexes
- Handling overlaps in summary indexes
- datamodel command basics
- data model acceleration overview
- accelerating a data model
- tsidx file structure
- tsidx file lifecycle
- tstats command fundamentals
- tstats with accelerated data models
- choosing acceleration options
- Splunk architecture components
- Search flow
- Streaming commands
- Transforming commands
- Command ordering
- Job inspector
- Pre-Filtering search data
- Lispy and boolean operators
- Lispy and wildcards
- Using the TERM directive
- Improving dashboard performance
- Using the tstats command
- Creating base searches
- Creating post-process searches
- Simple XML syntax for views
- View creation best practices
- Troubleshooting views
- Simple XML extensions
- Token fundamentals
- Tokens with form inputs
- Cascading inputs
- Token filters
- Predefined tokens
- Chart property customization
- Panel property customization
- Setting panel refresh intervals
- Setting panel delay times
- Disabling search access features
- Creating event annotations
- Types of Drilldowns
- Dynamic Drilldowns
- Event Handler Types
- Event Actions
- Contextual Drilldowns
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for core-certified-advanced-power-user, so none is invented.