Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Splunk: Zero to Power User
Bestseller
Rating: 4.3 out of 5(9,267 ratings)
42,299 students

Splunk: Zero to Power User

Splunk Core Certified Power User - Exam Prep - 2026!
Created byHailie Shaw
Last updated 12/2025
English
Arabic [Auto],German [Auto],

What you'll learn

  • Pass the Splunk Core Certified Power User exam!
  • Build SPLs, Dashboards, Reports, Alerts, and Searches
  • Go from having zero knowledge of Splunk to a Splunker with strong foundational skills
  • Understand how to hunt with Splunk
  • Gain more confidence in Crowdstrike's Event Search

Course content

1 section41 lectures4h 26m total length
  • Module 1: Introduction4:27

    Discover what Splunk is, why it serves as a SIEM and big data analytics platform, and how this course helps you pass the Splunk Core Certified Power User exam.

  • Module 2: What Makes Up Splunk5:38

    Understand Splunk's core components: forwarders, indexers, and search heads—and explore deployment options from standalone to multi-instance, including clustering and deployment servers for management.

  • Module 3A: Demo of Lets Download Splunk3:06

    Download the Splunk GUI installer from Splunk.com, start a free 60-day Splunk Enterprise trial for Windows 64-bit, run the GUI installer, set credentials, and access Splunk Web at loopback 8000.

  • Module 3B: MacOS Installation3:20

    Download the free 60-day trial of Splunk Enterprise for macOS, install via the wizard to the default /Applications path, then log in to Splunk Web on port 8000.

  • Module 3C: Demo of Getting the Practice Data9:44

    Upload practice data to Splunk using Cisco WSA and Unix add-ons, assign source types (access_combined, linux_secure), create indices (web, security, cisco), and run a search across all time to verify.

  • Module 4A: Getting Data into Splunk3:16

    Explore the Splunk data pipeline, from input and parsing to license tracking and indexing, and learn to configure inputs, data preview, and local log collection.

  • Module 4B: Demo of Data Preview and Creating Inputs8:41

    Demonstrate data preview and creating inputs in Splunk, comparing csv versus log formats and adjusting source types. Configure local event log and Windows host inputs for live search and analysis.

  • Module 4C: App vs Addon3:19

    Explore the difference between apps and add-ons in Splunk, including gui-driven apps on the search head and background technology add-ons (TAs) that onboard and optimize data.

  • Module 5: Demo of Searching and Basic Navigation13:24

    Master the basics of searching in Splunk by navigating the search bar, using time pickers and search modes, and exploring fields, events, and operators to build effective queries.

  • Module 6A: Knowledge Objects3:14

    Learn what knowledge objects are, how to create and manage them, and how permissions and naming conventions enable collaboration across apps in Splunk.

  • Module 6B: Demo of KOs8:03

    Demonstrate Splunk knowledge objects by creating an alert for excessive failed logins from a Russian IP, then configure permissions, throttling, and email alerts.

  • Module 7: Show me the Fields!3:35

    Define splunk fields as key-value pairs with case-sensitive names and case-insensitive values. Learn to search by one or multiple fields and use not operators to filter results.

  • Module 8A: Search Processing Language4:17

    Learn how Splunk's search processing language uses color-coded syntax—orange modifiers, blue commands, green arguments, and pink functions—while mastering table, rename, fields, dedupe, and sort.

  • Module 8B: Demo of Building SPLs and Basic Commands9:06

    Demonstrate building SPLs and using basic commands—table, rename, fields, dedupe, and sort—while exploring top values and totals in search and reporting.

  • Module 9A: Transforming Your Search2:05

    Explore transforming commands in Splunk, including top, rare, and stats, and learn how they convert event values into numerical data for analysis, with smart mode behavior and practical demos.

  • Module 9B: Transforming Commands9:43

    Explore transforming commands in Splunk, including top values and rare values, to analyze fields like category ID and refer domain. Apply stats, counts, and table formatting to reveal insights.

  • Module 10A: What are the Events Telling Me?3:08

    Explore how the transaction command groups related events into end-to-end conversations, using max span, max pause, starts with, and ends with, and contrast it with faster, resource-friendly stats command.

  • Module 10B: Demo of the Transaction Command8:47

    Learn to use the transaction command in Splunk to group events by session, set max duration, and study web and security data for user actions and 404s.

  • Module 11A: Manipulating Your Data1:52

    Master data manipulation with eval, where, and search to create calculated fields, filter results, and convert epoch time to readable dates, while understanding field overwriting and command placement.

  • Module 11B: Demo of eval, where, and search11:31
  • Module 12A: Fields, Part 2!2:36

    Explore advanced field handling in Splunk, including extracting new fields with regex and delimiters, and using rex and erex to generate or craft extractions.

  • Module 12B: Demo of Field Extracting9:20

    Learn to access Splunk’s field extractor in three ways, then create fields using the GUI, regular expressions rex and erex, and validate results with previews and permissions.

  • Module 13A: Lookups2:48

    Explore lookups in Splunk: define static data files, perform data enrichment by querying lookups, and create or upload lookups using input and output commands.

  • Module 13B: Demo of Using Lookups9:42

    learn to create and query lookups in splunk by uploading a csv, defining a lookup, and using input lookup with where filters to enrich searches and analyze product data.

  • Module 14A: Visualize Your Data3:04

    Visualize data in Splunk with tables, single values, gauges, bar, line charts, pie charts, maps, and learn to use stats, chart, and timechart with stacking, overlay, trellis, and multi-series.

  • Module 14B: Demo of Chart, Chart, Chart.....stats.15:30

    Explore how to create and customize visualizations in Splunk, including time charts, bar and pie charts, dashboards, and quick reports, with practical examples of actions, purchases, and failed logins.

  • Module 15A: Visualizations, Part 2!2:19

    Explore visualizations in Splunk as we cover iplocation, geostats, addtotals, and trendline to enhance panel dashboards with location insights, maps, totals, and moving averages for your analytics.

  • Module 15B: Demo of More Dashboards!10:21

    Explore building and refining Splunk dashboards with time charts, trend lines and SMA moving averages, then visualize geo data with IP location, geo stats, and cluster maps.

  • Module 16A: Reports & Drilldowns2:55

    Explore how to create, save, and manage reports and drilldowns in Splunk, including scheduling, naming best practices, token usage, and exporting dashboards to pdf for a home dashboard view.

  • Module 16B: Demo of Generating Reports, Drilldowns, Home Dashboard14:16

    Learn how to build a home dashboard in Splunk, create panels, pass tokens, add inputs, perform searches with time tokens, generate reports, and configure drilldowns and pdf exports.

  • Module 17: Alerts7:14

    Create and manage alerts in Splunk by configuring scheduled or real-time searches, setting trigger conditions, throttling, and actions like logging or emailing, with severity and permissions considered.

  • Module 18: Welcome, Tags and Events!5:45

    Explore tagging events and using event types to color-code and organize data in search and reporting, with practical demos of creating tags, applying colors, and analyzing login events.

  • Module 19A: Macros1:41

    Discover how to create and use macros in Splunk to save time on recurring searches, pass arguments, and manage macros via settings.

  • Module 19B: Demo of Making Macros9:53

    Learn to create and manage Splunk search macros, including examples like salesmade, top5, and fileinfo, and how to use arguments and expand the underlying search.

  • Module 20: Workflows to Save You Time7:31

    Learn to create and configure Splunk workflow actions, including GET, POST, and search actions, with an IP whois lookup demo to save time and verify results.

  • Module 21A: Data Normalization & Troubleshooting3:54

    Learn how to normalize data with field aliases and calculated fields using eval, manage Splunk buckets from hot to frozen, and use the job inspector for troubleshooting.

  • Module 21B: Demo of All the random things we just covered8:46

    Create field aliases for IP data across web, security, and Cisco as source_ip; build megs from bytes and inspect job performance and bucket states with dbinspect.

  • Module 22A: Datamodels3:59

    Discover how Splunk data models organize datasets into hierarchical structures to accelerate searches, using tstats, field aliases, and pivot tools for faster, normalized data analysis.

  • Module 22B: Demo of Searching Datamodels6:40

    Explore and manage Splunk data models, view and edit CIM-compliant data models, and use pivots and spl to search, count, and visualize data from web and authentication models.

  • Module 23A: The Common Information Model3:44

    Map your data to the common information model to enable CIM compliant searches with consistent field names, using 22 pre-configured data models, data normalization, and the CIM add-on builder.

  • Module 23B: Demo of the CIM Add-on & CIM Add-On Builder13:50

    Log into Splunk, install the CIM app, and map web data to the CIM Web data model using the add-on builder, field aliases, and data model mappings.

Requirements

  • Connection to the internet

Description

Hello and welcome to the course. This is the #1 place to learn by watching instructor lead demonstrations on Splunk. Don’t take another course that is bogged down with long lectures and endless PowerPoint slides. Take one that covers the majority of the course via recorded demonstrations and is built for visual learners!

This course is designed to take someone who has never heard of Splunk and provide them with the knowledge they need to pass the Splunk Core Certified Power User exam!

Is it hard to find a streamlined education road map for Splunks old Fundamentals 1 and 2 concepts? This course is it!

Learn by watching demonstrations for over 75% of the course!

Download your own data and practice on your own instance of Splunk.

Learn over 25 commands through many examples!

Gain confidence in how to craft strong searches, build visualizations, and understand the key components of Splunk.

This course will cover all the key topics you need to pass the exam!

I hope you continue to take what you have learned here and move on to learning more advanced topics that Splunk has to offer!

See you in the course and good luck on the exam!

Who this course is for:

  • Beginner Splunkers
  • SOC Analysts
  • Network Forensic Analysts
  • Splunk Admins
  • Splunk Power Users
  • Endpoint Detection and Response
  • Crowdstrike Users