
Splunk Core Certified Power User
The Splunk Core Certified Power User certification validates your ability to use Splunk Enterprise and Splunk Cloud to search, report, and create knowledge objects. It is designed for users who want to move beyond basic searching and start building workflow actions, data models, and normalized data. Earning this credential demonstrates you can turn raw machine data into actionable insights and sets you on the path to advanced Splunk roles.
494 practice questions · Updated 2026-07-30
10Domains
32Objectives
189Concepts
494Questions
SPLK-1002 Curriculum
Every domain, objective, and concept the SPLK-1002 exam measures.
- chart command syntax
- chart command functions
- chart command grouping and splitting
- chart command options
- chart command output format
- timechart basics
- timechart syntax
- timechart functions
- timechart by clause
- timechart time spans
- timechart options
- timechart with multiple series
- timechart vs chart
- timechart formatting
- eval command syntax
- arithmetic operators
- comparison operators
- logical operators
- if function
- case function
- match function
- like function
- in function
- string functions
- date and time functions
- statistical functions
- conversion functions
- creating and overwriting fields
- using eval with search results
- search command basics
- where command basics
- comparison operators
- logical operators
- wildcards in search
- field existence checks
- case sensitivity
- using quotes and escaping
- performance considerations
- Purpose of fillnull
- Basic fillnull syntax
- Specifying a custom value
- Filling specific fields
- Combining field and value arguments
- Impact on output
- Transaction command basics
- Transaction fields
- Transaction options
- Transaction vs stats
- Transaction examples
- Group events using fields
- Group events by fields
- Group events by time
- Combine field and time grouping
- transaction command basics
- transaction fields
- transaction options
- transaction output fields
- transaction vs stats
- transaction use cases
- Transaction command basics
- Transaction fields
- Transaction options
- Transaction output fields
- Transaction vs stats
- Transaction performance considerations
- Transaction command purpose
- Stats command purpose
- Transaction vs stats use cases
- Transaction command syntax
- Stats command syntax
- Transaction limitations
- Stats advantages
- Accessing the Field Extractor
- Selecting sample events for extraction
- Using the FX interactive extraction workflow
- Defining extraction rules with regex
- Validating extracted fields
- Saving and applying the extraction
- Understanding FX extraction
- Identifying delimiters
- Using the FX command syntax
- Handling quoted fields
- Testing and validating extractions
- Definition of field aliases
- Creating field aliases
- Using field aliases in searches
- Scope and precedence of field aliases
- Definition of calculated fields
- Creating calculated fields
- Using calculated fields in searches
- Editing and deleting calculated fields
- Understanding tags
- Creating tags
- Applying tags to events
- Managing tags
- Using tags in searches
- Tag inheritance and permissions
- Definition of Event Types
- Use Cases for Event Types
- Creating Event Types
- Managing Event Types
- Applying Event Types
- Event Types vs Tags
- Define event types
- Create event types
- Assign event type properties
- Use event types in searches
- Manage event types
- Definition of macros
- Macro syntax and usage
- Macro creation workflow
- Macro arguments and validation
- Macro management and permissions
- Define macro syntax
- Create a basic macro
- Use a macro in a search
- Understand macro scope and permissions
- Edit and delete a macro
- Macro argument definition
- Macro variable usage
- Default values for arguments
- Argument validation and constraints
- Passing arguments to macros
- Scope and naming of variables
- Macro argument syntax
- Passing arguments to macros
- Default values for macro arguments
- Argument validation and error handling
- Escaping special characters in arguments
- Using arguments in macro definitions
- GET workflow action
- POST workflow action
- Search workflow action
- Comparison of GET, POST, and Search actions
- Use cases for each action type
- Define GET workflow action
- Identify workflow action configuration options
- Create a GET workflow action
- Configure label and URI
- Apply workflow action to fields
- Test and verify workflow action
- Define POST workflow action
- Configure POST workflow action settings
- Set POST parameters and payload
- Use tokens in POST workflow actions
- Test and validate POST workflow action
- Define Search workflow action
- Configure Search workflow action settings
- Set search workflow action conditions
- Define search workflow action link behavior
- Use tokens in search workflow actions
- Test and validate search workflow actions
- Data model and pivot relationship
- Pivot creation from data models
- Data model constraints in pivots
- Pivot limitations and data model design
- Define data model attributes
- Identify attribute types
- Recognize attribute properties
- Understand attribute inheritance
- Apply attributes in searches
- Data model definition
- Data model components
- Dataset types
- Creating a data model
- Adding datasets
- Defining fields
- Field properties
- Data model hierarchy
- Saving and validating
- CIM Overview
- CIM Components
- CIM Data Models
- CIM Tags
- CIM Field Extractions
- CIM Add-On Functionality
- CIM Use Cases
- CIM Add-On knowledge objects overview
- CIM event types
- CIM tags
- CIM field extractions
- CIM lookups
- CIM data models
- Purpose of the CIM Add-On
- CIM data models and their structure
- Normalization process
- Using CIM add-on with data inputs
- Verifying normalized data
- Troubleshooting normalization issues
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for SPLK-1002, so none is invented.