SPLK-1002 Exam Guide: Skills, Study Plan, and Scheduling Decisions
SPLK-1002 is associated in the supplied catalogue context with Splunk Core Certified Power User, an entry-level certification for people who need to search, report on, and extend Splunk data with reusable knowledge objects. Splunk’s current certification page does not display the code “SPLK-1002” in its visible text, so confirm the exam name and code in Pearson VUE before paying. This guide helps you decide whether your practical Splunk skills are ready, which blueprint domains need the most work, and whether test-center or online delivery fits your situation.
What does SPLK-1002 validate?
The exam validates practical use of Splunk Enterprise and Splunk Cloud capabilities beyond basic searching. Its scope includes searching and reporting, workflow actions, event types, knowledge objects, data models, field aliases, calculated fields, macros, and data normalization with the Splunk Common Information Model (CIM).
The credential is officially presented as Splunk Core Certified Power User. Splunk describes it as an entry-level exam intended to help candidates strengthen searching and reporting capabilities and deliver more value as power users. The certification applies to users of both Splunk Enterprise and Splunk Cloud platform software.
In practical terms, the exam is not only a test of whether you can write a search that returns events. It also examines whether you understand how to make results useful to other users: improve fields, classify events, reuse search logic, connect actions to workflows, and prepare data for consistent analysis.
The catalogue context supplied for this page uses the identifier SPLK-1002, while the reviewed official Splunk page does not visibly show that identifier. Treat the official credential name as the primary confirmation when you check registration details, and verify that the code shown in your Pearson VUE account matches the exam you intend to take.
Who is the exam for?
This exam suits analysts, operations staff, security practitioners, application support specialists, and other Splunk users who already work with searches and need to build repeatable reporting or knowledge objects. It can also suit a candidate moving from the Core Certified User level toward more advanced power-user or administration work.
It is not presented as an administrator certification. Splunk lists Splunk Core Certified Advanced Power User, Splunk Enterprise Certified Admin, and Splunk Cloud Certified Admin as related next-step certifications. Those pathways can help you choose a longer-term direction, but they are not prerequisites for this exam.
What are the official exam requirements and format?
The exam has no prerequisite certifications or prerequisite courses. Splunk lists the exam length as 60 minutes, including time to review the certification agreement, and the format as 65 multiple-choice questions. The listed price is $130 USD per exam attempt. Confirm the live registration page before purchase because scheduling, availability, and program information can change.
Splunk states that Pearson VUE delivers the exam. Pearson VUE offers two delivery methods for Splunk exams: a proctored appointment at an Authorized Test Center and a self-administered online-proctored appointment. The same Pearson account is used to schedule or purchase either type of exam.
The time limit makes concise interpretation important. You need to recognize what a search, command, knowledge object, or data-model choice is intended to accomplish rather than spending the entire appointment reconstructing every option from first principles. Practice should therefore include explanation and selection, not only command typing.
How should you interpret the code and credential name?
Use the exam title shown by the official registration flow as your final check. The current official Splunk materials identify the credential associated with this exam as Splunk Core Certified Power User, and they do not display “SPLK-1002” in the visible text reviewed for this guide. The exam was previously available as Splunk Phantom Certified Admin, which is useful context if older study material uses that name.
Do not assume that a third-party page, old PDF, or practice product with a familiar code represents the current registration item. Before scheduling, open the Splunk certification page and Pearson VUE’s Splunk page, sign in, and compare the displayed title and code.
What does the appointment process require?
Pearson VUE requires exam appointments to be made at least 24 hours in advance, based on availability. Use the links on the Pearson VUE Splunk page to sign in, schedule the appointment, and either submit the fee or enter a voucher code. Choose the delivery method only after checking the requirements for your location and equipment.
For changes, Pearson VUE states that cancellation or rescheduling must be completed a minimum of 48 hours before the appointment. Exams cannot be cancelled or rescheduled less than 48 hours before the appointment. Failure to cancel or reschedule in time, or failure to appear, results in forfeiture of the exam fee.
Create a scheduling buffer rather than selecting the earliest possible slot. This gives you time to run the online system test if you choose OnVUE, resolve an identity-document issue, or move the appointment without approaching the 48-hour cutoff.
Which blueprint domains deserve the most study time?
Study the blueprint by domain, not by a flat list of Splunk commands. Correlating events carries the largest single allocation at 15%, while transforming commands for visualizations carries 5%; the remaining listed domains each carry 10%. Use those labels when deciding where to spend review time, and do not treat an isolated command as a complete topic.
The official blueprint assigns 15% to correlating events, including transactions, grouping events, and choosing between transactions and stats. This domain deserves deliberate comparison practice because the decision is about the relationship between events and the kind of result required, not memorizing one preferred command.
The official blueprint assigns 5% to transforming commands for visualizations, including the chart and timechart commands. This is the smallest listed domain, but it still needs hands-on practice: know what shape of result a visualization command expects and how that differs from a search that simply filters events.
The official blueprint assigns 10% to filtering and formatting results, covering eval, search, where, and fillnull. Practice the purpose and placement of each command, including how a command changes the available fields or the rows returned.
The official blueprint assigns 10% to creating and managing fields. The official blueprint assigns 10% to field aliases and calculated fields. Treat these as related but separate decisions: one concerns field creation and management generally, while the other focuses on ways fields can be represented or derived.
The official blueprint assigns 10% to tags and event types. Practice identifying when classification improves search consistency and how these knowledge objects support users who should not have to remember every raw-value variation.
The official blueprint assigns 10% to macros. Your revision should cover the role of reusable search fragments, their inputs, and the effect of using a macro rather than copying search text between reports.
The official blueprint assigns 10% to workflow actions. Study the relationship between an event or search result and the action a user can take from it. Focus on the purpose and configuration logic rather than trying to memorize undocumented examples.
The official blueprint assigns 10% to data models. Connect this domain to structured analysis: understand what a data model represents, how it organizes data for use, and why its design affects the consistency of downstream searches or reports.
The official blueprint assigns 10% to using the Common Information Model Add-on, including describing CIM, identifying its knowledge objects, and normalizing data with CIM. Review CIM as a normalization framework and learn to distinguish normalized field concepts from the source-specific fields that may require mapping.
How should you turn the percentages into a study schedule?
Start with the 15% correlating events domain, then give equal planned attention to the six 10% domains that match your weakest practical skills. Reserve a short focused block for the 5% visualization domain. This is a planning recommendation based on the official blueprint, not a prediction of the order or wording of questions.
A useful allocation method is to create a checklist with one row per official domain. Mark each row as unfamiliar, partly usable, or reliable. Spend your first study cycle learning every domain, your second cycle repairing the unfamiliar and partly usable areas, and your final cycle mixing domains so that you must choose the right technique without being prompted by a chapter title.
How should you prepare if you have basic Splunk experience?
Build from search-result control to reusable knowledge objects. First make sure you can read and modify searches; then connect those searches to fields, classifications, macros, workflow actions, data models, and CIM. This sequence prevents you from memorizing configuration terms without understanding the results they are intended to improve.
Use a working Splunk environment, where available, to test small searches and compare outputs. The goal is not to reproduce live exam questions. Instead, create your own controlled examples with a known set of events, change one command or object at a time, and record what changed in the result.
For each practice task, write a one-sentence explanation of why your chosen approach fits. For example, explain why a grouped result is sufficient or why event correlation is needed, why a calculated field belongs in a reusable definition, or why CIM normalization matters when data comes from different sources. Explanation exposes gaps that successful command execution can hide.
What should you study first?
Begin with the areas that influence almost every later topic: search interpretation, fields, filtering, and result formatting. Then move to event correlation and statistical or visualization-oriented results. Finish the first pass with knowledge objects, data models, and CIM so that you understand how searches become reusable and consistent across users.
Splunk’s recommended preparation courses include Working with Time, Statistical Processing, Comparing Values, Result Modification, Correlation Analysis, Creating Knowledge Objects, Creating Field Extractions, and Data Models. Use these official recommendations to map your training rather than relying on an unrelated general Splunk course.
A sensible sequence is:
1. Working with Time and basic result interpretation.
2. Result Modification, including filtering and formatting decisions.
3. Statistical Processing and Comparing Values.
4. Correlation Analysis.
5. Creating Field Extractions and the broader knowledge-object topics.
6. Data Models and CIM normalization.
If your work already involves advanced searches but little configuration, reverse the emphasis after the first diagnostic session. The best sequence is the one that closes your largest skill gap while preserving enough search fluency to understand the objects you create.
How can you practise fields and knowledge objects?
Use one small dataset and turn the same information into several representations. Identify fields, test a calculated field, consider an alias, classify suitable values with tags or event types, and encapsulate repeated logic in a macro. For each exercise, note the user problem solved and the scope at which the object should be managed.
Avoid learning these objects as interchangeable labels. A field alias is not the same design decision as a calculated field; a tag is not a replacement for an event type; and a macro is not merely a saved report. Ask what should be consistent, what should be derived, what should be classified, and what search text should be reused.
Then test maintenance questions. What happens if a field name changes? Which users need the object? Would a copied search drift from the original? Does a classification help users find events, or does it conceal an unresolved data-quality issue? These questions build the judgment that scenario-based multiple-choice items often require, without claiming to reproduce exam content.
How should you practise event correlation?
Compare transactions, grouping events, and stats using the same conceptual problem. First define what makes events related, then identify whether you need a transaction-like event grouping, a grouped summary, or statistical aggregation. The official blueprint explicitly includes choosing between transactions and stats, so practice the choice as carefully as the syntax.
Write down the expected output before running the search: one row per event, one row per group, or a calculated summary. If the output you receive does not match that expectation, inspect the grouping key, time relationship, and command behavior instead of adding commands at random.
A common mistake is choosing the most elaborate method because it appears to capture more context. A better approach is to choose the method that produces the required result with an understandable relationship between events. Keep performance and maintainability in mind as practical considerations, while studying the exact concepts and terminology in the official blueprint.
How should you review CIM and data models?
Treat CIM and data models as connected but distinct study areas. A data model organizes a defined set of fields and events for structured analysis; CIM provides normalized field and object conventions so that comparable data can be analyzed consistently. Learn what each contributes before attempting to memorize object names.
Create a mapping exercise from source-specific fields to normalized concepts. Note which source fields are missing, which names differ, and which values need consistent interpretation. Then ask how the normalized result would support a report or data-model search. This makes CIM a practical data-understanding task rather than a vocabulary-only exercise.
The blueprint calls for describing CIM, identifying its knowledge objects, and normalizing data with CIM. Make each of those three verbs a separate checklist item. If you can describe the purpose but cannot identify the relevant object or explain the normalization step, the topic is not yet ready for final review.
What does a practical study roadmap look like?
Use a four-stage roadmap: diagnose, build, integrate, and verify. The stages are more useful than an arbitrary calendar because they adapt to your starting skill and available time. Do not schedule the exam until you can explain your choices across the blueprint without relying on copied notes or question memorization.
Stage 1 — Diagnose your gaps. Read the official blueprint and create a domain checklist. Attempt small tasks involving filtering, visualization, event correlation, fields, aliases, calculated fields, tags, event types, macros, workflow actions, data models, and CIM. Record not only wrong answers but also answers you reached by guessing.
Stage 2 — Build one domain at a time. Work through the official preparation-course subjects, pairing each lesson with a short hands-on task. After every task, write the command or object’s purpose, the expected result shape, and one nearby concept it should not be confused with.
Stage 3 — Integrate the domains. Build a small reporting workflow from raw events to useful fields, a filtered result, a grouped or statistical output, and a reusable object. Add a classification or normalization decision where appropriate. The point is to practise transitions between domains because real work rarely presents them in isolated chapters.
Stage 4 — Verify readiness. Use a self-made mixed review that asks you to select an approach and justify it. Revisit every uncertain domain. Read the blueprint again and check that your notes cover its named topics, especially the comparison between transactions and stats and the stated CIM objectives.
If your time is limited, protect the diagnostic and integration stages. Reading every topic without testing whether you can apply it creates false confidence. Conversely, repeatedly building one polished dashboard will not prove that you understand macros, workflow actions, or normalization.
What should a weekly study session contain?
A focused session should include recall, application, and correction. Begin by explaining a concept without opening notes, apply it in a controlled Splunk task, and finish by documenting the mistake or ambiguity you found. This cycle is more informative than passively rereading a course section.
A sample session structure is:
1. Review one or two blueprint domains and state their boundaries.
2. Complete a short search or configuration exercise.
3. Compare the result with your expected output.
4. Explain why an alternative technique would produce a different result.
5. Add the unresolved issue to a review list.
Keep a separate “confusion pairs” page. Examples include filtering versus formatting, aliases versus calculated fields, event grouping versus statistical aggregation, and a reusable macro versus a saved report. Review this page at the end of each study cycle.
When are you ready to schedule?
Schedule when you can work across the blueprint rather than when one favourite topic feels comfortable. Readiness means you can identify the task being asked, select a suitable Splunk capability, and reject plausible alternatives for a reason. It does not require memorizing leaked questions, and dumps or exam-question memorization cannot guarantee a passing result.
Before booking, verify the current exam title and identifier in Pearson VUE, check your preferred delivery method, and confirm that your study plan leaves time for a final mixed review. Because appointments must be made at least 24 hours in advance and changes generally require 48 hours’ notice, choose a date that leaves a realistic contingency window.
Should you choose a test center or OnVUE?
Choose a Pearson VUE test center if you prefer a controlled testing location or do not want to manage the online technical and room requirements. Choose OnVUE only after you have passed the system test on the same computer and network you plan to use. Both options are official delivery routes, but their preparation tasks differ.
For OnVUE, Pearson VUE lists Windows 10 or macOS 14 or higher, a working webcam, microphone, and speaker, no headphones or headsets, one display screen, and a stable internet connection with at least 6 Mbps download and 2 Mbps upload. You must be able to close all applications except OnVUE.
Pearson VUE also prohibits virtual machines or beta operating systems, VPNs, corporate networks, and public or shared networks for the stated online requirements. Run and pass the system test on the same device and network before exam day, restart the computer, and ensure that other network users are not streaming or performing large downloads.
The testing space must be quiet, private, and free of distractions. The desk must be empty except for the testing computer, pre-approved items, comfort aids, and a beverage in an unmarked container. Remove books, notes, paper, pens, electronics, bags, and other listed personal items, and clear whiteboards or note boards.
During online check-in, you complete technology checks, photograph yourself and your identification, and perform a 360° room scan. Pearson VUE instructs candidates to begin check-in 30 minutes before the appointment. If a requirement is not met, you cannot test and the fee may be forfeited.
Bring an accepted valid government-issued ID with a recognizable photo whose name exactly matches the exam booking. Pearson VUE lists accepted examples such as an international passport, plastic driver’s license, national, state, provincial, or EU ID card, alien registration card, approved Aadhaar cards, and certain other listed IDs. Expired, digital, damaged, copied, and privately issued IDs are prohibited, so check the current OnVUE page rather than assuming an employer badge will work.
Online rules also prohibit cheating, another person taking the exam, recording or sharing the screen, leaving webcam view without an approved break, speaking or reading aloud unless instructed, and accessing a phone unless explicitly permitted. A violation can revoke the exam and forfeit the fee. If technical trouble occurs, use the in-exam chat; a proctor cannot pause or extend the exam or troubleshoot your device or network.
What should you do during check-in and the agreement?
Allow more time than the appointment start for identity and environment checks. At a Pearson testing center, candidates receive 3 minutes to read and sign Splunk’s Non-Disclosure Agreement once seated. Candidates who do not agree within the 3 minutes are excused and forfeit the examination fee, according to Pearson VUE’s Splunk policy.
Because the total exam length is 60 minutes including review of the certification agreement, read scheduling and check-in instructions in advance rather than using exam time to learn the process. Follow the current Pearson VUE instructions for your selected delivery method.
What mistakes waste preparation time?
The most expensive preparation mistake is studying by command name instead of by outcome. A candidate may recognize eval, stats, chart, or a macro in isolation yet still choose incorrectly when a question describes the required result or reusable behavior. Always connect a technique to the problem it solves and the output it produces.
Mistake one: treating the blueprint as a vocabulary list. Correct it by turning every named domain into an action: filter, format, correlate, create, manage, classify, reuse, trigger, model, or normalize.
Mistake two: spending all study time on ordinary searches. Correct it by building knowledge objects and practising how a search changes when fields are aliased, calculated, classified, or normalized.
Mistake three: avoiding comparisons. Correct it by writing short “use this when” notes for transactions versus stats, aliases versus calculated fields, and event types versus tags. Do not write a rule that is broader than the official objective; test the distinction with your own small examples.
Mistake four: using unofficial question banks as the main preparation source. Such material can contain stale, incorrect, or improperly disclosed content. It also encourages recognition without understanding. Use the official blueprint and recommended courses as the foundation, then create original practice tasks.
Mistake five: postponing delivery planning. Correct it by checking identification, room, device, network, appointment, and cancellation requirements before you commit the fee. Online candidates who do not meet system requirements at exam time can be treated as a failure to appear.
Mistake six: ignoring the naming transition. If your notes say Splunk Phantom Certified Admin, compare them with the current Splunk Core Certified Power User page and current blueprint. Do not assume older terminology is a complete description of the present exam.
How should you review wrong answers?
Classify each miss by cause: missing concept, incorrect output expectation, confused terminology, careless reading, or time pressure. Then repair the cause with a targeted task. Repeating the same question until the option looks familiar does not show that the underlying skill has improved.
For a concept miss, return to the official course or blueprint topic. For an output miss, run a controlled search and inspect the result shape. For a terminology miss, add the term to a comparison table. For time pressure, practise selecting the task and eliminating unsuitable options before worrying about every detail.
What should you do after passing or postponing?
After passing, keep the credential aligned with Splunk’s current certification guidance. Splunk describes recertification options that include pursuing additional certifications, completing continuing education courses, or retaking the certification exam every three years. Check the current certification page for the option that applies to your credential.
If you postpone, preserve your domain checklist and record the specific reason: a weak blueprint area, missing hands-on access, uncertain delivery setup, or an appointment constraint. A postponement is useful when it converts a vague intention to study into a short list of actions. If you do not pass, follow Pearson VUE’s current retake policy before choosing another appointment.
Pearson VUE states that a candidate who does not pass on the first attempt must wait 7 days to retake a Splunk Certification Exam. Its published table gives a second-attempt schedule by day of the week, and candidates who do not pass on the second attempt must wait 14 days. Subsequent retakes are listed as third attempt 4 weeks or 28 days, fourth attempt 8 weeks or 56 days, and fifth attempt 8 weeks or 56 days; retakes beyond the fifth attempt are considered case by case.
Do not book a retake simply because the waiting period has ended. Review the score information available to you, identify the weakest domains, and change the study method. If the issue was delivery readiness or appointment administration, fix that operational problem before repeating technical study.
What are sensible next certifications?
Choose the next credential according to the work you want to perform. Splunk lists Splunk Core Certified Advanced Power User, Splunk Enterprise Certified Admin, and Splunk Cloud Certified Admin as related next-step certifications. The advanced power-user route extends search and reporting depth, while the Enterprise and Cloud administrator routes point toward platform administration responsibilities.
The Core Certified User credential is a separate entry-level certification focused on Splunk Enterprise and Splunk Cloud basics, including searching, fields and lookups, alerts, basic statistical reports, and dashboards. If those fundamentals are not secure, strengthen them before treating power-user topics as isolated configuration knowledge.
What is the final readiness checklist?
Before scheduling, confirm the credential name and code in the official registration flow, then use the blueprint to test every domain. Your final decision should rest on demonstrated understanding, not on the number of pages read or the familiarity of a question bank.
Use this checklist:
1. I can describe what the Splunk Core Certified Power User exam is intended to validate.
2. I have reviewed every official blueprint domain and identified my weakest areas.
3. I can explain filtering and formatting with eval, search, where, and fillnull.
4. I can distinguish event correlation, grouping, and statistical approaches, including the transactions-versus-stats decision.
5. I understand the purpose of fields, field aliases, calculated fields, tags, event types, macros, and workflow actions.
6. I can explain what data models contribute and what CIM normalization is intended to achieve.
7. I have practised the official recommended preparation subjects that match my gaps.
8. I have completed mixed, original exercises instead of relying on recalled or leaked exam content.
9. I have selected a test center or verified every OnVUE requirement on the intended device and network.
10. I know that appointments require at least 24 hours’ advance scheduling and that cancellation or rescheduling generally requires 48 hours’ notice.
11. I have a valid, acceptable identification document whose name matches my booking.
12. I have left a scheduling buffer so a technical, identity, or study issue does not force a late cancellation.
Once these items are true, schedule through the official Pearson VUE route and keep the blueprint available for focused final review. If several items remain uncertain, delay the appointment and turn each uncertainty into a small, testable study task.
Conclusion
SPLK-1002 preparation is best treated as a practical Splunk skills project: understand search results, make fields and classifications useful, choose the right correlation or visualization approach, and connect data models and CIM to consistent analysis. Confirm the current Splunk Core Certified Power User title and code before registration, use the official blueprint to prioritize study, and make delivery planning part of readiness. The next action is simple: open the blueprint, mark each domain as reliable or unresolved, and schedule only when the unresolved list is small and specific.