Splunk Core Certified Power User exam is the final step towards completion of the Splunk Core Certified Power User certification. This next-level certification exam evaluates a candidate’s knowledge and skills of field aliases and calculated fields, creating tags and event types, using macros, creating workflow actions and data models, and normalizing data with the CIM. This certification demonstrates an individual's foundational competence of Splunk’s core software.
Splunk Core Certified Power User has a basic understanding of SPL searching and reporting commands and can create knowledge objects, use field aliases and calculated fields and normalize data with the Common Information Model in either the Splunk Enterprise or Splunk Cloud platforms.
Splunk Core Certified Power User is a required prerequisite to the Splunk Enterprise Certified Admin certification track.
Candidates for the exam are recommended to complete the lecture, hands-on labs, and quizzes that are part of the Splunk Fundamentals 2 course for preparing for the certification exam. This course focuses on searching and reporting commands, as well as on the creation of knowledge objects.
The topics covered in this exam include:
1. Using Transforming commands and visualizations – 5%
2. Filtering and formatting results – 10%
3. Correlating events – 15%
4. Knowledge objects – 10%
5. Fields (field aliases, field extractions, calculated fields) – 10%
6. Tags and event types – 10%
7. Macros – 10%
8. Workflow actions – 10%
9. Data models – 10%
10. Splunk Common Information Model (CIM) – 10%