Exam Outline
The Splunk core certified user exam covers eight domains:
- Splunk Basics – 5%
- Basic Searching – 22%
- Using Fields in Searches – 20%
- Search Language Fundamentals – 15%
- Using Basic Transforming Commands – 15%
- Creating Reports and Dashboards – 12 %
- Creating and Using Lookups – 6%
- Creating Scheaduled Reports and alerts – 5%
Example questions
- What are the main components of Splunk?
- Splunk forwarder, indexer, search head
- Splunk indexer, heavy forwarder, search head
- Splunk indexer, deployment manager, forwarder
- Splunk heavy forwarder, deployment manager, splunk indexer
- When you install Splunk on a stand-alone machine, which components are on it?
- input data
- parser
- indexer
- all of the above
- When you install the Splunk Enterprise free 60-day trial version, what is you daily index size?
- 100 MB
- 500 MB
- 750 MB
- 1000 MB
- A ………….. displays statistical trends over time.
- chart value
- time series
- stats value
- table value
- The …………. command can display any series of data you want to plot.
- chart
- stat
- time chart
- both 1 and 2
- Which are filtering commands in Splunk?
- where, dedup, and head
- dedup, head, and tail
- where, dedup, and tail
- all of the above
- A transaction is a grouping command.
- true
- false
More about exam
Notes:
- Splunk basics – componets, usages, apps, add-ons, customizing user settings, basic navigation in Splunk.
- Basic Searching – run basic search, time range, search results, refine searches, timeline, events, search job, save search results.
- Using Fields in Searches – fields, fields in searches, sidebar.
- Search Language Fundamentals – general search practices, basic search commands, search pipeline, indexes in search, table, rename, fields, dedup, sort.
- Using basic transforming commands – top, rare, stats.
- Creating Reports and Dashboards – save a search as a report, edit reports, create reports to display statistics, visualizations, charts, add a report to a dashboard, edit dashboard.
- Creating and Using Lookups – lookups, lookup file, lookup definition, automatic lookup, lookup in searches.
- Creating Scheaduled Reports and Alerts – scheduled report, configuration of scheduled reports, alerts.
Sources
Sources (Examples of questions):
- https://docs.splunk.com/Documentation/Splunk/8.1.2/SearchReference/Stats
- https://www.apress.com/gp/book/9781484266687
- https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transaction
Some sources for test preparations:
- https://www.testpreptraining.com/tutorial/splunk-core-certified-user-splk-1001/
- https://vceguide.com/splunk/
- https://www.examtopics.com/exams/splunk/splk-1001/view/
- https://www.itexams.com/info/SPLK-1001
- https://www.itexams.com/exam/SPLK-1001
Exam: – https://wsr.pearsonvue.com/