Exam objectives

Core Certified User

Splunk Core Certified User exam objectives

The published blueprint is the contract: the exam can only test what is on this list. Domains carry their official weightings, and objectives with a practice page link straight to questions written for that objective.

Titles and weightings from the official objectives. Splunk exam page

Splunk Basics

5%of exam
  • 1.1 Splunk componentsIn the bank

  • 1.2 Understand the uses of SplunkIn the bank

  • 1.3 Define Splunk appsIn the bank

  • 1.4 Customizing user settingsIn the bank

  • 1.5 Basic navigation in SplunkIn the bank

Basic Searching

22%of exam

Using Fields in Searches

20%of exam

Search Language Fundamentals

15%of exam

Using Basic Transforming Commands

15%of exam

Creating Reports and Dashboards

12%of exam
  • 6.1 Save a search as a reportIn the bank

  • 6.2 Edit reportsPractice
  • 6.3 Create reports that display statistics (tables)In the bank

  • 6.4 Create reports that display visualizations (charts)In the bank

  • 6.5 Create a dashboardIn the bank

  • 6.6 Add a report to a dashboardIn the bank

  • 6.7 Edit a dashboardIn the bank

Creating and Using Lookups

6%of exam
  • 7.1 Describe lookupsIn the bank

  • 7.2 Examine a lookup file exampleIn the bank

  • 7.3 Create a lookup file and create a lookup definitionIn the bank

  • 7.4 Configure an automatic lookupIn the bank

  • 7.5 Use the lookup in searchesIn the bank

Creating Scheduled Reports and Alerts

5%of exam
  • 8.1 Describe scheduled reportsIn the bank

  • 8.2 Configure scheduled reportsIn the bank

  • 8.3 Describe alertsIn the bank

  • 8.4 Create alertsIn the bank

  • 8.5 View fired alertsIn the bank

Objectives marked Practice open a page of original questions written for that objective, each with a full explanation cited to Splunk documentation.

Keep reading

Every guide and cost breakdown, by vendor