Courseiva
SPLK-1002Free Study Guide

Splunk Core Certified User SPLK-1002The Complete Beginner's Guide

This guide covers the official exam objectives for the Splunk Core Certified User SPLK-1002 certification, focusing on Splunk basics, fields and lookups, basic searching, and reports/dashboards.

17 chapters
~3 hours total read
Free — no signup required
By Johnson Ajibi · Senior Network & Security Engineer · MSc IT Security

How to use this guide

This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.

① Read a chapter② Answer practice questions③ Review missed answers④ Repeat
Study Chapters

17 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.

Start Chapter 1
Practice Questions

Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.

Go to practice test
Glossary

Every SPLK-1002term defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.

Browse glossary
Exam Overview

Exam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.

View exam guide

Chapters — SPLK-1002

1

Splunk Overview and Core Architecture

Objective 1.1 · Describe the Splunk architecture and its components

12m
2

Navigating the Splunk Web Interface

Objective 1.2 · Navigate the Splunk web interface and understand its key elements

12m
3

Understanding Indexes and Data Inputs

Objective 1.3 · Explain the role of indexes and data inputs in Splunk

12m
4

Fields Extraction and Usage

Objective 2.1 · Define fields and describe how they are extracted from events

12m
5

Working with Default and Calculated Fields

Objective 2.2 · Use default fields and create calculated fields to enrich search results

12m
6

Lookups: Basics and Creation

Objective 2.3 · Explain the purpose of lookups and how to create them

12m
7

Advanced Lookup Operations

Objective 2.4 · Use lookup commands and manage lookup table files

12m
8

Introduction to the Search Processing Language

Objective 3.1 · Describe basic Splunk search syntax and components

12m
9

Basic Search Commands and the Pipeline

Objective 3.2 · Execute basic searches using commands, keywords, and the pipe

12m
10

Search-Time Transformations and the eval Command

Objective 3.3 · Use eval and other search-time transformations to manipulate data

12m
11

Filtering and Formatting Search Results

Objective 3.4 · Filter events with where, search, and format results using fields, rename, and sort

12m
12

Grouping and Analyzing Data with stats

Objective 3.5 · Group events and compute statistics using the stats command

12m
13

Other Statistical Commands (top, rare, chart, timechart)

Objective 3.6 · Use top, rare, chart, and timechart to summarize data

12m
14

Subsearches and Advanced Filtering

Objective 3.7 · Perform subsearches and use advanced filtering techniques

12m
15

Creating and Managing Reports

Objective 4.1 · Create, save, and schedule reports based on search results

12m
16

Fundamentals of Dashboards

Objective 4.2 · Build dashboards using panels, forms, and time range pickers

12m
17

Dashboard Interactivity and Sharing

Objective 4.3 · Add interactive elements and share dashboards with others

12m

Ready to test your knowledge?

Free SPLK-1002 practice questions with full explanations. Test what you learn chapter by chapter.

SPLK-1002 Practice Questions