This guide covers the official exam objectives for the Splunk Core Certified User SPLK-1002 certification, focusing on Splunk basics, fields and lookups, basic searching, and reports/dashboards.
This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.
17 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.
Start Chapter 1Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.
Go to practice testEvery SPLK-1002term defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.
Browse glossaryExam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.
View exam guideSplunk Overview and Core Architecture
Objective 1.1 · Describe the Splunk architecture and its components
Navigating the Splunk Web Interface
Objective 1.2 · Navigate the Splunk web interface and understand its key elements
Understanding Indexes and Data Inputs
Objective 1.3 · Explain the role of indexes and data inputs in Splunk
Fields Extraction and Usage
Objective 2.1 · Define fields and describe how they are extracted from events
Working with Default and Calculated Fields
Objective 2.2 · Use default fields and create calculated fields to enrich search results
Lookups: Basics and Creation
Objective 2.3 · Explain the purpose of lookups and how to create them
Advanced Lookup Operations
Objective 2.4 · Use lookup commands and manage lookup table files
Introduction to the Search Processing Language
Objective 3.1 · Describe basic Splunk search syntax and components
Basic Search Commands and the Pipeline
Objective 3.2 · Execute basic searches using commands, keywords, and the pipe
Search-Time Transformations and the eval Command
Objective 3.3 · Use eval and other search-time transformations to manipulate data
Filtering and Formatting Search Results
Objective 3.4 · Filter events with where, search, and format results using fields, rename, and sort
Grouping and Analyzing Data with stats
Objective 3.5 · Group events and compute statistics using the stats command
Other Statistical Commands (top, rare, chart, timechart)
Objective 3.6 · Use top, rare, chart, and timechart to summarize data
Subsearches and Advanced Filtering
Objective 3.7 · Perform subsearches and use advanced filtering techniques
Creating and Managing Reports
Objective 4.1 · Create, save, and schedule reports based on search results
Fundamentals of Dashboards
Objective 4.2 · Build dashboards using panels, forms, and time range pickers
Dashboard Interactivity and Sharing
Objective 4.3 · Add interactive elements and share dashboards with others
Free SPLK-1002 practice questions with full explanations. Test what you learn chapter by chapter.
SPLK-1002 Practice Questions