Core Certified UserSplunk Core Certified User

Practice Exam 2

5 of this form’s 60 questions, drawn from across its domains, free. The explanation on every one of them is free too, at every tier, and always will be.

  1. Question 1 of 5

    2-8Basic Searching

    A user has written a search they expect to run again next week. Which Save As option does Splunk describe for that?

  2. Question 2 of 5

    3-3Using Fields in Searches

    A user adds three fields to Selected Fields and notices some events show only two of them. What does Splunk say about that?

  3. Question 3 of 5

    4-2Search Language Fundamentals

    A team wants a chart from raw events. What does Splunk say a search must do before a visualization can be drawn?

  4. Question 4 of 5

    5-2Using Basic Transforming Commands

    A user asks what the showcount option does on the rare command. What does Splunk document?

  5. Question 5 of 5

    6-1Creating Reports and Dashboards

    A team asks where a report can be built from in Splunk Web. Which two starting points does Splunk name?

0 of 60 completed

0%

The other 55 questions are the rest of this form: same 60 minute clock, same 750 cut score, and the same explanation on every question, which is never behind the wall. Practice Exam 2 of 2 on Core Certified User.

What this exam covers

  • Splunk Basics3 questions / 5% of the exam
  • Basic Searching13 questions / 22% of the exam
  • Using Fields in Searches12 questions / 20% of the exam
  • Search Language Fundamentals9 questions / 15% of the exam
  • Using Basic Transforming Commands9 questions / 15% of the exam
  • Creating Reports and Dashboards7 questions / 12% of the exam
  • Creating and Using Lookups4 questions / 6% of the exam
  • Creating Scheduled Reports and Alerts3 questions / 5% of the exam

Checking what you already have access to.

Every question is original, written from the published objectives. We never reproduce, paraphrase, or imitate real exam content, and neither should anything else you study from.