Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by Splunk
Exam Format
Registration
Validity
SPLK-1002 Exam Topics and Domains
SPLK-1002 is organized into 10 weighted domains. Expect to work with SPL, Splunk Web, Knowledge Objects, CIM Add-On, and more.
Using Transforming Commands for Visualizations
Use the chart command
- Understand the chart command syntax and its various options
- Create multi-series charts using the by clause
- Apply statistical functions within chart commands
Use the timechart command
- Create time-based visualizations using timechart
- Control time span and bucketing in timechart
- Apply advanced timechart options for complex visualizations
Filtering and Formatting Results
The eval command
- Create calculated fields using eval
- Apply eval functions for data manipulation
- Use conditional logic in eval expressions
Use the search and where commands to filter results
- Filter search results using the search command
- Apply where command for expression-based filtering
- Understand when to use search vs where
The fillnull command
- Replace null values in search results
- Apply fillnull to specific fields or all fields
- Set appropriate default values for null fields
Correlating Events
Identify transactions
- Understand what transactions are in Splunk
- Identify events that belong to the same transaction
- Recognize transaction patterns in data
Group events using fields
- Group related events using common fields
- Create transactions based on field values
- Use the transaction command effectively
Group events using fields and time
- Create transactions with time constraints
- Define transaction boundaries using time and fields
- Apply maxspan and maxpause parameters
Search with transactions
- Search and filter transaction results
- Use transaction-specific fields in searches
- Analyze transaction duration and event counts
Creating and Managing Fields
Perform regex field extractions using the Field Extractor (FX)
- Create field extractions using regular expressions
- Use the Field Extractor interface effectively
- Validate and test field extractions
Perform delimiter field extractions using the FX
- Extract fields from delimiter-separated data
- Configure delimiter-based extractions
- Handle various delimiter types
Creating Field Aliases and Calculated Fields
Describe, create, and use field aliases
- Understand the purpose of field aliases
- Create and configure field aliases
- Apply field aliases to normalize data
Describe, create, and use calculated fields
- Create calculated fields using eval expressions
- Configure automatic field calculations
- Apply calculated fields in searches
Creating Tags and Event Types
Create and use tags
- Create and manage tags
- Apply tags to field-value pairs
- Use tags effectively in searches
Describe event types and their uses
- Understand event type concepts
- Recognize use cases for event types
- Differentiate event types from other knowledge objects
Create an event type
- Create event types from searches
- Configure event type properties
- Apply event types to categorize data
Creating and Using Macros
Describe macros
- Understand search macro concepts
- Recognize benefits of using macros
- Identify appropriate use cases for macros
Create and use a basic macro
- Create basic search macros
- Invoke macros in searches
- Test and validate macro functionality
Define arguments and variables for a macro
- Define arguments for macros
- Understand variable substitution
- Create flexible, parameterized macros
Add and use arguments with a macro
- Invoke macros with arguments
- Pass multiple arguments to macros
- Validate macro argument usage
Creating and Using Workflow Actions
Describe the function of GET, POST, and Search workflow actions
- Understand different workflow action types
- Identify appropriate action type for use cases
- Recognize workflow action capabilities
Create a GET workflow action
- Create GET workflow actions
- Configure URL parameters
- Pass field values to external resources
Create a POST workflow action
- Create POST workflow actions
- Configure POST parameters
- Submit data to external applications
Create a Search workflow action
- Create Search workflow actions
- Build dynamic search strings
- Configure search time ranges
Creating Data Models
Describe the relationship between data models and pivot
- Understand data model architecture
- Recognize the relationship between data models and pivot
- Create basic data models for pivot reporting
Using the Common Information Model (CIM) Add-On
Describe the Splunk CIM
- Understand the Common Information Model
- Recognize benefits of data normalization
- Identify CIM use cases
List the knowledge objects included with the Splunk CIM Add-On
- Identify knowledge objects in CIM
- Understand CIM data model categories
- Recognize CIM field conventions
Use the CIM Add-On to normalize data
- Apply CIM to normalize data sources
- Map custom fields to CIM standards
- Validate CIM compliance
How do I earn this certification?
Passing SPLK-1002 earns the Splunk Core Certified Power User certification. It sits in the Splunk Core track.
- SPLK-1004 - Splunk Cloud Certified AdminCloud platform administration focus
- SPLK-1005 - Splunk Enterprise Certified AdminOn-premises administration focus
- SPLK-3001 - Splunk Enterprise Security Certified Admin Security operations specialization
- SPLK-3002 - Splunk Phantom Certified AdminSecurity orchestration and automation
- SPLK-3003 - Splunk SOAR Certified Automation DeveloperAutomation development specialization
- SPLK-4001 - Splunk O11y Cloud Certified Metrics UserObservability and metrics focus
- SPLK-5001 - Splunk Certified Cybersecurity Defense AnalystCybersecurity defense specialization
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
The most effective way to prepare for SPLK-1002 is by using the PlanetCert Simulator to practice questions and review detailed explanations.
What's changed on this exam?
- ACTIVE
- Last content update: 2024
- Search Processing Language (SPL) Latest Core focus area - 40% of exam content • Release date: Ongoing
- Common Information Model (CIM) 5.x 10% of exam - normalization concepts critical • Release date: 2024
- Splunk Web Framework Latest Workflow actions and dashboard creation • Release date: Ongoing
Who should take this exam?
This exam is typically taken by IT professionals seeking Splunk expertise and Data analysts working with machine data.
- Splunk Fundamentals 1
- Splunk Fundamentals 2
- 3-6 months of hands-on Splunk experience
- Experience with searching and reporting in Splunk
- Basic understanding of SPL (Search Processing Language)