Exam objectives

Core Certified Advanced Power User

Splunk Core Certified Advanced Power User exam objectives

The published blueprint is the contract: the exam can only test what is on this list. Domains carry their official weightings, and objectives with a practice page link straight to questions written for that objective.

Titles and weightings from the official objectives. Splunk exam page

Exploring Statistical Commands

4%of exam
  • 1.1 Performing statistical analysis with stats functionIn the bank

  • 1.2 Using fieldsummaryIn the bank

  • 1.3 Using appendpipeIn the bank

  • 1.4 Using count and list functions

  • 1.5 Using eventstatsIn the bank

  • 1.6 Using streamstatsIn the bank

Exploring eval Command Functions

4%of exam
  • 2.1 Using conversion functionsIn the bank

  • 2.2 Using text functionsIn the bank

  • 2.3 Using comparison and conditional functionsIn the bank

  • 2.4 Using informational functionsIn the bank

  • 2.5 Using statistical functions

  • 2.6 Using makeresults command

Exploring Lookups

4%of exam
  • 3.1 Applying advanced lookup optionsIn the bank

  • 3.2 Including and excluding events based on lookup values

  • 3.3 Using KV Store lookupsIn the bank

  • 3.4 Using external lookupsIn the bank

  • 3.5 Using geospatial lookupsIn the bank

  • 3.6 Understanding best practices for lookupsIn the bank

Exploring Alerts

4%of exam
  • 4.1 Logging and indexing searchable alert eventsIn the bank

  • 4.2 Referencing lookups in alertsIn the bank

  • 4.3 Outputting alert results to a lookupIn the bank

  • 4.4 Using a webhook alert actionIn the bank

  • 4.5 Creating a log event alert action

Advanced Field Creation and Management

4%of exam

Working with Self-Describing Data and Files

3%of exam
  • 6.1 Understanding self-describing dataIn the bank

  • 6.2 Using the spath commandIn the bank

  • 6.3 Using the eval command with the spath functionIn the bank

  • 6.4 Using the multikv commandIn the bank

Advanced Search Macros

3%of exam
  • 7.1 Using nested search macrosIn the bank

  • 7.2 Previewing search macros before executingIn the bank

  • 7.3 Using other knowledge objects with macrosIn the bank

Using Acceleration Options: Reports and Summary Indexing

4%of exam
  • 8.1 Describing accelerationIn the bank

  • 8.2 Identifying which reports qualify for accelerationIn the bank

  • 8.3 Identifying when Splunk doesn’t build an acceleration summaryIn the bank

  • 8.4 Accelerating a reportIn the bank

  • 8.5 Using the Report Acceleration Summaries and Summary Detail pages

  • 8.6 Understanding summary Indexing

  • 8.7 Using the summary indexing transforming commands

  • 8.8 Defining searching against a summary

  • 8.9 Understanding how to handle gaps and overlaps in summary indexes

Using Acceleration Options: Data Models and tsidx Files

4%of exam
  • 9.1 Exploring data models using the datamodel commandIn the bank

  • 9.2 Understanding data model accelerationIn the bank

  • 9.3 Accelerating data modelsIn the bank

  • 9.4 Understanding tsidx filesIn the bank

  • 9.5 Working with tsidx files using tstats commandsIn the bank

  • 9.6 Using tstats to search accelerated data modelsIn the bank

  • 9.7 Determining which acceleration option to use

Using Search Efficiently

4%of exam
  • 10.1 Splunk architecture componentsIn the bank

  • 10.2 Search flowIn the bank

  • 10.3 Streaming commandsIn the bank

  • 10.4 Transforming commands

  • 10.5 Command orderingIn the bank

  • 10.6 Job inspectorIn the bank

More Search Tuning

3%of exam
  • 11.1 Pre-Filtering search dataIn the bank

  • 11.2 Lispy and boolean operatorsIn the bank

  • 11.3 Lispy and wildcardsIn the bank

  • 11.4 Using the TERM directiveIn the bank

Manipulating and FIltering Data

6%of exam
  • 12.1 bin commandIn the bank

  • 12.2 xyseries commandIn the bank

  • 12.3 untable commandIn the bank

  • 12.4 foreach commandIn the bank

  • 12.5 strftime functionIn the bank

Working with Multivalued Fields

7%of exam

Using Advanced Transactions

5%of exam

Working with Time

2%of exam
  • 15.1 Using time effectivelyIn the bank

  • 15.2 What are the default time fieldsIn the bank

Using Subsearches

6%of exam
  • 16.1 Filtering through many resultsIn the bank

  • 16.2 Subsearch caveatsIn the bank

  • 16.3 When to use subsearchIn the bank

  • 16.4 When NOT to use subsearchIn the bank

  • 16.5 Troubleshooting subsearchesIn the bank

  • 16.6 append commandIn the bank

Creating a Prototype

4%of exam

Using Forms

5%of exam
  • 18.1 Explain how tokens workIn the bank

  • 18.2 Use tokens with form inputsIn the bank

  • 18.3 Create cascading inputsIn the bank

  • 18.4 Define types of token filtersIn the bank

Improving Performance

6%of exam

Customizing Dashboards

6%of exam

Adding Drilldowns

7%of exam

Adding Advanced Behaviors and Visualizations

5%of exam
  • 22.1 Identify types of event handlersIn the bank

  • 22.2 Define event actionsIn the bank

  • 22.3 Create contextual drilldownsIn the bank

  • 22.4 Use simple XML extensionsIn the bank

Objectives marked Practice open a page of original questions written for that objective, each with a full explanation cited to Splunk documentation.

Keep reading

Every guide and cost breakdown, by vendor