
Splunk Core Certified User
The Splunk Core Certified User certification validates your ability to search, use fields and lookups, and create alerts, basic statistical reports, and dashboards in Splunk Enterprise and Splunk Cloud. Designed for those with little to no Splunk experience, it is the entry point to the Splunk certification program and demonstrates you can turn data into action.
743 practice questions · Updated 2026-07-30
8Domains
40Objectives
211Concepts
743Questions
SPLK-1001 Curriculum
Every domain, objective, and concept the SPLK-1001 exam measures.
- Identify Splunk components
- Describe the role of the forwarder
- Describe the role of the indexer
- Describe the role of the search head
- Explain how components work together
- Define Splunk
- Identify Splunk uses
- Describe Splunk components
- Understand Splunk data flow
- Definition of Splunk apps
- Components of a Splunk app
- App vs. add-on distinction
- App installation and management
- Accessing user settings
- Changing password
- Setting time zone
- Configuring default app
- Managing user preferences
- Basic search syntax
- Search modes
- Time range selection
- Search execution and results
- Search history and saved searches
- Understanding time ranges in Splunk
- Using the time range picker
- Setting time range via search syntax
- Using relative time ranges
- Using absolute time ranges
- Applying time range to subsearches
- Adjusting time range after search
- Interpreting search result fields
- Recognizing event data
- Understanding timestamps in results
- Identifying source, sourcetype, and host
- Reading the results table
- Distinguishing between raw and field values
- Using the fields sidebar
- Recognizing result count and time range
- Search refinement techniques
- Time range selection
- Search modes
- Field selection and filtering
- Search history and saved searches
- Timeline overview
- Interpreting timeline bars
- Zooming and panning
- Selecting time ranges
- Resetting the timeline
- Event Anatomy
- Event Timeline
- Event Actions
- Event Details
- Event Selection
- Start and stop a search job
- Pause and resume a search job
- Finalize a search job
- Monitor search job progress
- Manage search job properties
- View and export search job results
- Delete a search job
- Save search results
- Export search results
- Save as report
- Save as dashboard panel
- Manage saved searches
- Definition of fields
- Default fields
- Field-value pairs
- Fields sidebar
- Selected and interesting fields
- Field extraction basics
- Using fields in search syntax
- Displaying and hiding fields
- Field-value pairs in searches
- Working with multi-value fields
- Field aliases and calculated fields
- Accessing the fields sidebar
- Understanding field roles
- Using the fields sidebar for filtering
- Interpreting field statistics
- Managing field visibility
- Basic search commands
- General search practices
- Search pipeline overview
- Search head and indexer roles
- Search artifacts and job management
- Data flow in search
- Index specification syntax
- Default index behavior
- Multiple index specification
- Index wildcard usage
- Index listing and validation
- tables command
- rename command
- fields command
- dedup command
- sort command
- Purpose of the top command
- Syntax and basic usage
- Default behavior and output fields
- Limiting results with limit
- Grouping with by clause
- Using countfield and showcount options
- Using percentfield and showperc options
- Handling other fields with showfields
- Combining top with other commands
- Purpose of the rare command
- Basic syntax
- Count and percent fields
- Sorting behavior
- Using with by-clause
- Limiting results
- Comparison with top command
- stats command syntax
- common stats functions
- grouping with by clause
- renaming output fields
- multiple stats functions
- grouping by multiple fields
- using stats with time
- handling null values
- comparing stats to other transforming commands
- Report definition
- Saving a search as a report
- Report naming and permissions
- Scheduling reports
- Report actions and management
- Edit report properties
- Edit report search
- Edit report time range
- Edit report visualization
- Edit report permissions
- Edit report schedule
- Save edited report
- Understanding statistics tables
- Creating a statistics table
- Selecting fields for statistics
- Applying statistical functions
- Formatting statistics tables
- Chart Types
- Creating Charts
- Configuring Chart Properties
- Formatting Data for Charts
- Interacting with Charts
- Saving as Reports
- Dashboard creation workflow
- Dashboard panels
- Dashboard inputs
- Dashboard layout and formatting
- Dashboard saving and sharing
- Adding a report to a dashboard
- Selecting a dashboard
- Placing the report on the dashboard
- Configuring report panel settings
- Saving and viewing the dashboard
- Accessing Dashboard Edit Mode
- Editing Dashboard Panels
- Adding and Removing Panels
- Rearranging Panels
- Editing Dashboard Title and Description
- Saving Dashboard Changes
- Definition of lookups
- Lookup file types
- Lookup use cases
- Static vs. dynamic lookups
- Identify lookup file structure
- Interpret lookup file content
- Understand lookup file usage
- Create a lookup file
- Create a lookup definition
- Purpose of automatic lookups
- Prerequisites for automatic lookups
- Configuration steps for automatic lookups
- Applying automatic lookups to specific sourcetypes
- Testing and verifying automatic lookups
- Lookup command syntax
- Using lookups in search
- Output field handling
- Lookup input field matching
- Handling missing lookup values
- Definition of scheduled reports
- Scheduling frequency and time range
- Delivery and sharing options
- Permissions and access
- Scheduled report status and monitoring
- Scheduled report creation
- Schedule configuration options
- Report delivery and permissions
- Scheduled report management
- Definition of alerts
- Alert types
- Alert actions
- Alert conditions
- Alert severity and throttling
- Alert creation basics
- Alert types
- Alert conditions and triggers
- Alert actions
- Alert scheduling
- Alert throttling
- Alert permissions and ownership
- Alert testing and validation
- Accessing fired alerts
- Interpreting fired alert details
- Managing fired alerts
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for SPLK-1001, so none is invented.