Version honesty is a rare thing in this market, and Prep4cram practices it for SPLK-1002: the Splunk Core Certified Power User bank is checked against vendor updates every day, and if a refresh is ever pending, the team says so openly instead of overselling what is on the shelf.
Splunk SPLK-1002 Exam Overview:
| Certification Vendor: | Splunk |
|---|---|
| Exam Name: | Splunk Core Certified Power User Exam |
| Exam Number: | SPLK-1002 |
| Related Certifications: | Splunk Enterprise Certified Admin Splunk Core Certified Advanced Power User |
| Exam Duration: | 60 minutes |
| Exam Price: | $130 USD |
| Real Exam Qty: | 65 |
| Certificate Validity Period: | 2 years |
| Available Languages: | English |
| Exam Format: | Multiple response, Multiple choice |
| Passing Score: | 70% |
| Recommended Training: | Splunk Fundamentals 2 Official Splunk Certification Page |
| Exam Registration: | Pearson VUE Registration |
| Sample Questions: | ![]() |
| Exam Way: | Online proctored or onsite at Pearson VUE test centers |
| Pre Condition: | No required prerequisites; recommended to complete Splunk Fundamentals 2 course and have 3–6 months of hands-on experience |
| Official Syllabus URL: | https://www.splunk.com/en_us/training/certification-track/splunk-core-certified-power-user.html |
Splunk SPLK-1002 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Using Macros | 10% | - Manage macro permissions and sharing - Create and reuse search macros - Add and use arguments in macros |
| Using the Common Information Model (CIM) Add-On | 5% | - Normalize data using CIM knowledge objects - Describe Splunk CIM purpose and structure - Use CIM to standardize data across sources |
| Correlating Events | 15% | - Compare transactions vs stats commands - Group events by fields and time - Identify and use transactions |
| Creating Tags and Event Types | 10% | - Create and apply tags to fields or values - Use tags and event types in searches - Define event types to categorize events |
| Creating and Using Field Aliases and Calculated Fields | 10% | - Manage field extractions and aliases - Create calculated fields with eval - Define and use field aliases |
| Filtering and Formatting Results | 15% | - Use search and where commands - Use fillnull, eval, and other formatting commands - Sort, rename, and limit results |
| Creating and Using Workflow Actions | 10% | - Describe GET, POST, and Search workflow actions - Use workflow actions to extend searches - Create and configure workflow actions |
| Creating Data Models | 10% | - Create and use data models - Define data model objects and attributes - Understand data models and Pivot |
| Transforming Commands and Visualizations | 15% | - Use transforming commands to structure data - Format results for presentation - Create and customize visualizations |
SPLK-1002 Exam Details, Version Policy and Customer Perks
- Creating and Using Field Aliases and Calculated Fields (10%)
- Creating and Using Workflow Actions (10%)
- Creating Data Models (10%)
Splunk Core Certified Power User Sample Questions:
Consider the the following search run over a time range of last 7 days:
index=web sourcetype=access_conbined | timechart avg(bytes) by product_nane Which option is used to change the default time span so that results are grouped into 12 hour intervals?
- A. span=12
- B. timespan=12h
- C. span=12h
- D. timespan=12
Correct Answer: C 🗳️
Explanation: Only visible for Prep4cram members. You can sign-up / login (it's free).
Given the event below, how can the value in the Zip_Code field be used to retrieve the local weather from an external resource?
25/Oct/2023:20:29:43 , 151.131.173.143 , V2.003 , Zip_Code: 75890 , DataCenter: DC1
- A. Create a POST workflow action.
- B. Create a GET workflow action.
- C. Create a PUT workflow action.
- D. Create a Search workflow action.
Correct Answer: B 🗳️
Explanation: Only visible for Prep4cram members. You can sign-up / login (it's free).
When using multiple expressions in a single eval command, which delimiter is used?
- A. , (comma)
- B. : (colon)
- C. I (pipe)
- D. / (forward slash)
Correct Answer: A 🗳️
Explanation: Only visible for Prep4cram members. You can sign-up / login (it's free).
Where are the results of eval commands stored?
- A. In a KV Store.
- B. In an index.
- C. In a database.
- D. In a field.
Correct Answer: D 🗳️
Explanation: Only visible for Prep4cram members. You can sign-up / login (it's free).
Using the export function, you can export search results as __________.( Select all that apply)
- A. A php file
- B. Xml
- C. Json
- D. Html
Correct Answer: B,C 🗳️
Explanation: Only visible for Prep4cram members. You can sign-up / login (it's free).






