


Splunk Core Certified Power User (SPLK-1002) - Practice Tests
This course is designed to accelerate your preparation for the Splunk Core Certified Power User (SPLK-1002) exam by offering 186 exam-aligned practice questions (all unique, no duplicates) covering all major exam domains. The practice tests simulate real exam conditions and focus on SPL and knowledge-object skills: transforming commands, filtering and formatting, correlating events, field extractions, tags, event types, macros, workflow actions, data models, pivot, and the CIM.
# Key Topics Covered:
* Transforming commands for visualizations: chart and timechart
* Filtering and formatting: eval, search/where, and fillnull
* Correlating events: transactions, grouping by fields/time, transaction vs. stats
* Field extractions with the Field Extractor (regex and delimiter methods)
* Field aliases and calculated fields
* Tags, event types, and search macros (with arguments)
* GET / POST / Search workflow actions
* Data models, Pivot, and the Common Information Model (CIM) Add-On
Each practice test is crafted based on the official exam blueprint and helps you assess readiness, reinforce concepts, and boost confidence before the real exam.
# Disclaimer:
This is NOT an official course and is NOT affiliated with, authorized by, endorsed by, or sponsored by Splunk Inc. or any other original equipment manufacturer (OEM) or certification body. Splunk Inc., its logos, the exam code SPLK-1002, and all related product names are trademarks or registered trademarks of their respective owners and are used here for identification and descriptive purposes only. These practice tests are created independently, solely for exam preparation, self-assessment, and educational practice. They do NOT contain any real or actual exam questions, and scoring well on these practice tests does not guarantee that you will pass the official certification exam.
# Know the Syllabus and Content:
Before attempting the real exam, make sure you are fully aware of the current official exam syllabus, objectives, and content outline published by Splunk Inc.. These questions are aligned to the official exam blueprint below, but exam objectives can change over time. Always confirm the latest official blueprint and study the official materials alongside these practice tests.
# Exam Content:
1.0 Using Transforming Commands for Visualizations 5%
* 1.1 Use the chart command
* 1.2 Use the timechart command
2.0 Filtering and Formatting Results 10%
* 2.1 The eval command
* 2.2 Use the search and where commands to filter results
* 2.3 The fillnull command
3.0 Correlating Events 15%
* 3.1 Identify transactions
* 3.2 Group events using fields
* 3.3 Group events using fields and time
* 3.4 Search with transactions
* 3.5 Report on transactions
* 3.6 Determine when to use transactions vs. stats
4.0 Creating and Managing Fields 10%
* 4.1 Perform regex field extractions using the Field Extractor (FX)
* 4.2 Perform delimiter field extractions using the FX
5.0 Creating Field Aliases and Calculated Fields 10%
* 5.1 Describe, create, and use field aliases
* 5.2 Describe, create, and use calculated fields
6.0 Creating Tags and Event Types 10%
* 6.1 Create and use tags
* 6.2 Describe event types and their uses
* 6.3 Create an event type
7.0 Creating and Using Macros 10%
* 7.1 Describe macros
* 7.2 Create and use a basic macro
* 7.3 Define arguments and variables for a macro
* 7.4 Add and use arguments with a macro
8.0 Creating and Using Workflow Actions 10%
* 8.1 Describe the function of GET, POST, and Search workflow actions
* 8.2 Create a GET workflow action
* 8.3 Create a POST workflow action
* 8.4 Create a Search workflow action
9.0 Creating Data Models 10%
* 9.1 Describe the relationship between data models and pivot
* 9.2 Identify data model attributes
* 9.3 Create a data model
10.0 Using the Common Information Model (CIM) Add-On 10%
* 10.1 Describe the Splunk CIM
* 10.2 List the knowledge objects included with the Splunk CIM Add-On
* 10.3 Use the CIM Add-On to normalize data