SPLK-1002 Exam Guide: Splunk Core Certified Power User Preparation and Scheduling
SPLK-1002 is commonly used to refer to the Splunk Core Certified Power User exam, although the current Splunk pages reviewed identify the credential by name rather than displaying that code. It validates entry-level ability to search, report, correlate events, and build reusable Splunk knowledge objects across Splunk Enterprise and Splunk Cloud platform software. Use this guide to decide whether your current skills fit the exam, organize practice by blueprint domain, and schedule with fewer avoidable risks.
Confirm that this is the right Splunk exam
The Splunk Core Certified Power User exam suits people who need to move beyond basic searching into repeatable analysis, reporting, and knowledge-object work. It is classified as entry-level, but its scope is more specific than a general introduction to the Splunk platform.
Splunk says the certification applies to users of both Splunk Enterprise and Splunk Cloud platform software. The official description emphasizes searching and reporting, workflow actions, event types, knowledge objects, data models, field aliases, calculated fields, macros, and data normalization with Splunk CIM.
A candidate who can run a simple search but cannot explain why a field is available, reusable, normalized, or transformed should treat the exam as a skills-building target rather than a quick credential. Conversely, someone whose daily work includes building reports and managing shared search knowledge should focus on closing blueprint gaps rather than relearning every basic interface action.
There are no prerequisite certifications or prerequisite courses. That is an access rule, not a recommendation to skip foundations. If search syntax, fields, and basic reports are still unfamiliar, build that base first. Splunk describes its Core Certified User credential as covering Splunk Enterprise and Splunk Cloud basics, including searching, fields and lookups, alerts, basic statistical reports, and dashboards; that scope is a useful readiness reference even when it is not a formal requirement.
Use the credential name when scheduling
Search and scheduling records should be checked against the current official credential name, Splunk Core Certified Power User. The reviewed official pages do not show “SPLK-1002” in their visible text, so do not rely on the code alone when selecting an appointment.
Before paying or applying a voucher, compare the exam title in the Pearson VUE catalog with the current Splunk certification-track page. This small check prevents choosing an exam based on a third-party label that may not match the current catalog wording.
Know what the exam measures
The blueprint tests whether you can make search results useful and reusable, not merely recognize command names. Preparation should therefore pair each topic with a task: write the search, inspect its output, and explain why that command or knowledge object fits the stated need.
The official blueprint’s largest domain is correlating events. Correlating events accounts for 15% and includes transactions, grouping events, and choosing between transactions and stats. This is a decision-making domain: practice identifying the relationship a question is trying to reveal before selecting an approach.
Filtering and formatting results accounts for 10% and covers eval, search, where, and fillnull. Build enough familiarity to distinguish filtering that narrows events from expressions that derive or modify fields, and from steps that address missing values.
Creating and managing fields accounts for 10%. Field aliases and calculated fields account for 10%. Tags and event types account for 10%. Macros account for 10%. Workflow actions account for 10%. Data models account for 10%. Using the Common Information Model Add-on accounts for 10%, including describing CIM, identifying its knowledge objects, and normalizing data with CIM.
Transforming commands for visualizations accounts for 5% and includes chart and timechart. Do not dismiss it because it is smaller. A compact domain can still expose uncertainty about which command produces the required shape of result.
The listed blueprint weights total the stated domains. That makes the blueprint a better study plan than a random list of Splunk commands: it tells you both what to practice and where a weak area has broad consequences.
Turn objectives into observable practice
A useful practice log records the task, the command or object selected, the expected result, the actual result, and the reason for any correction. This creates evidence of understanding that notes alone rarely provide.
For example, create paired exercises in which one goal is to connect related events and another is to summarize values. Then write a short justification for using a transaction-oriented approach, event grouping, or stats. The point is not to memorize a preferred command; it is to recognize the condition that makes a choice appropriate.
For field-related domains, use one consistent event set and deliberately test a field alias, a calculated field, a tag, an event type, and a macro as separate objects. Label the problem each object solves. Candidates often blur these concepts because all can make later searches easier, yet they serve different reuse and classification purposes.
Set a realistic readiness threshold
You are ready to schedule when you can solve blueprint-aligned tasks without depending on a copied search and can explain the purpose of each major object involved. A readiness decision should be based on balanced capability, not on one strong reporting topic.
Start with a short diagnostic covering every official domain. Use your own practice environment or authorized learning materials, then mark each task as independent, partly supported, or not yet understood. Avoid treating a correct result as mastery if you cannot reproduce the reasoning after a break.
Give special attention to boundaries that lead to plausible but wrong answers: search versus where, field alias versus calculated field, tags versus event types, and transaction-oriented correlation versus stats-based summarization. Those distinctions are more valuable than expanding a glossary with isolated definitions.
If a task fails, identify the failure type. Was the data narrowed too early? Did an expected field not exist? Was the result transformed into an unsuitable form? Did the reusable object solve the wrong problem? Repairing the reason is more durable than saving a revised query without notes.
Avoid low-value study shortcuts
Do not make exam dumps or alleged live questions part of the plan. They can be inaccurate, may conflict with exam confidentiality, and do not build the command-selection judgment the blueprint describes. Use official blueprint objectives and legitimate hands-on exercises instead.
Likewise, do not spend most study time collecting command syntax. The assessment scope includes choices among objects and methods, such as selecting transactions or stats for correlation. Practice starts with the analytical need and ends with an interpretable result. Syntax reference can support that work, but it should not replace it.
Build skills in a productive order
A strong sequence starts with results and fields, then builds reusable knowledge objects, and only then combines those skills in correlation, data models, and CIM. This order reduces confusion because later subjects assume you can inspect and shape events confidently.
First, work through filtering and formatting results. Use exercises that require search, where, eval, and fillnull separately before combining them. Ask what each step changes: the event set, a condition, a calculated value, or the treatment of missing values. This is an effective corrective for searches that work accidentally but cannot be explained.
Next, develop a field foundation. Create and manage fields, then distinguish field aliases from calculated fields through repeated examples. A practical decision rule is to state whether the need is to provide another field name or calculate a value; if you cannot state that clearly, revisit the object’s purpose before moving on.
Then study tags, event types, macros, and workflow actions together as ways to make analysis repeatable or connected to a next action. Keep separate notes for classification, saved search logic, and navigation or external-action behavior. Similar-looking names are not evidence that the objects are interchangeable.
Move to visual transformations after you can produce clean result sets. Practice deciding whether chart or timechart better matches the requested visualization-oriented transformation. Finish the core search sequence with correlation analysis, where transactions, grouping events, and the choice between transactions and stats must be tied to the problem wording.
Study data models and the Common Information Model Add-on after the earlier knowledge-object work. The CIM domain is not simply a vocabulary exercise: the blueprint includes identifying CIM knowledge objects and normalizing data with CIM. Explain the relationship between a normalized field approach and an analysis use case in your own words.
Use Splunk’s recommended course topics as a checklist
Splunk’s recommended preparation courses map well to a structured plan: Working with Time, Statistical Processing, Comparing Values, Result Modification, Correlation Analysis, Creating Knowledge Objects, Creating Field Extractions, and Data Models.
Treat those course names as topic anchors rather than assuming that attendance alone establishes readiness. After each topic, complete a small task with no step-by-step prompt. If you need to reopen the lesson for every decision, repeat the task with a different objective before progressing.
Follow a practical study roadmap
Use short cycles of learn, build, explain, and revisit. The roadmap below is deliberately organized by dependencies rather than an arbitrary calendar because available study time and prior Splunk experience vary.
Phase one is baseline search work: filtering, formatting, field creation, and result modification. Build a notebook of results that shows what changes after each command. Do not rush into a saved object until you can tell whether the issue originates in the search, the field, or the display.
Phase two is knowledge-object discipline: field aliases, calculated fields, tags, event types, macros, and workflow actions. For each, write one sentence describing its intended purpose and one sentence describing what it is not for. This makes later multiple-choice elimination more reliable.
Phase three is analytical structure: chart, timechart, transactions, grouping, and stats-based correlation choices. Use scenarios with near-identical data but different questions, such as a time-oriented trend versus a summary by category, or a connected event sequence versus an aggregate comparison. The changing objective should drive the choice.
Phase four is data-model and CIM work. Review the terms, identify the relevant knowledge objects, and practice explaining normalization as an analytical consistency task. Connect it back to fields and reports so it is not learned as an isolated final module.
Phase five is review and scheduling. Revisit every domain from a blank page, not only the ones you enjoy. Create a personal error list with concise corrections, then perform mixed-domain practice where the first task is to identify the domain being tested. This resembles the real decision of recognizing a problem before choosing a tool.
Use a final review that finds weak links
In final review, switch from topic blocks to mixed tasks. A candidate who succeeds only when a task is labeled “macros” may still struggle to recognize when a macro is relevant in a broader scenario.
Review errors by concept, not by answer choice. If several misses involve fields, separate them into creation, aliasing, calculation, and normalization. If several misses involve correlation, separate failure to recognize related events from failure to select an appropriate method. This turns an error log into a targeted revision queue.
Plan for the exam format and pace
The official exam format is 65 multiple-choice questions, and the total exam length is 60 minutes, including time to review the certification agreement. Plan concise decision-making: recognize the tested objective, eliminate options that solve a different problem, and reserve time to revisit uncertain items if the delivery interface permits.
Because the agreement review is included in the total time, do not treat the full session as answer time. During preparation, practice reading a scenario for its goal, identifying the relevant domain, and committing to a reasoned choice without turning every item into a long command-writing exercise.
The official page lists the exam price as $130 USD per attempt. Treat the fee as a scheduling factor rather than a reason to book before you are ready. A focused final review, a confirmed test setup, and a calendar reminder for policy deadlines are practical safeguards.
Splunk states that Pearson VUE delivers the exam. Pearson VUE says appointments must be made at least 24 hours in advance, based on availability. Book with enough room to complete setup checks and to respond to an unexpected scheduling conflict before the cancellation or rescheduling cutoff.
Apply the retake rules to your booking decision
A failed first attempt requires a 7-day wait before a retake. A candidate who does not pass a second attempt must wait 14 days to retake, while later attempts have longer stated waiting periods. Plan your first date as a genuine attempt, not a low-information rehearsal.
If a retake becomes necessary, use the required wait to diagnose domains rather than immediately repeating the same study routine. Return to the blueprint, identify the underlying skill gap, complete hands-on practice, and only then resume mixed review.
Choose test center or online delivery deliberately
Pearson VUE offers proctored delivery at authorized test centers and self-administered online proctored exams. Select the option that gives you the most controllable environment, not merely the one that appears most convenient.
Pearson VUE says the same Pearson account is used to schedule or purchase either exam type. Use the official Splunk Pearson VUE page to sign in, schedule online, and submit the fee or voucher code; use the links under the Splunk logo to locate a test center.
For online delivery, Pearson VUE requires candidates to meet the published system and environment requirements. A candidate who schedules an online appointment but does not meet system requirements at exam time is considered a failure to appear. Run the system test on the same device and network intended for the appointment, as Pearson VUE instructs.
Online check-in includes required technology checks, photos of the candidate and ID, and a 360° room scan. If a requirement is not met, testing cannot proceed and the fee is forfeited. Clear the space and test equipment before exam day rather than trying to solve setup problems during check-in.
Prepare the online environment if using OnVUE
Pearson VUE’s published minimum online technology requirements include Windows 10 or macOS 14 (or higher), a working webcam, microphone, and speaker, one display screen only, and a stable internet connection with at least 6 Mbps download and 2 Mbps upload. The same page prohibits virtual machines, beta operating systems, phones, tablets, headphones, earbuds, styluses, watches, VPNs, corporate networks, public or shared networks, and secondary or touchscreen displays.
The practical action is to make a written preflight list: use the same device and network for the system test, restart the computer, close other applications, disconnect or cover extra displays if they cannot be removed, and ensure another person is not consuming bandwidth with streaming or large downloads. Pearson VUE specifically advises passing the system test on the same device and network used on exam day.
Pearson VUE says to begin check-in 30 minutes before the appointment. Have a valid government-issued photo ID whose name exactly matches the booking. The online rules also prohibit another person from viewing the screen and prohibit recording, sharing the screen, leaving webcam view without an approved break, speaking or reading aloud unless instructed, and accessing a phone unless a proctor explicitly permits it. Violations can revoke the exam and forfeit the fee.
Protect the appointment from avoidable loss
The key scheduling deadline is 48 hours: Pearson VUE requires cancellation or rescheduling at least 48 hours before the appointment. Missing that deadline or failing to appear results in forfeiture of the exam fee.
Put two reminders in your calendar when you book: one before the 48-hour deadline to decide whether to keep the appointment, and one before check-in. If your plan changes, use the Pearson account or contact Pearson VUE rather than assuming a late change can be accommodated.
At a Pearson testing center, candidates are given 3 minutes after being seated to read and sign Splunk’s Non-Disclosure Agreement. Pearson VUE says candidates who decline or do not agree within the 3 minutes will be excused and forfeit the entire examination fee. Read the agreement promptly and do not attempt to retain, record, or share exam content.
For online testing, reserve a private, quiet room where you can remain alone. Pearson VUE lists public spaces such as offices, libraries, and coffee shops among prohibited spaces. Remove notes, paper, pens, electronics, bags, and other listed items from the desk area. This preparation also prevents a last-minute decision about where to test.
Know what to do if online testing has an issue
If an issue occurs during an online exam, Pearson VUE directs candidates to use the in-exam chat to reach a proctor. The proctor cannot pause or extend the exam or troubleshoot the device or network.
Pearson VUE advises closing and relaunching OnVUE from the downloads folder if the computer freezes or disconnects, then using the customer service page if issues persist. Keep this as an operational reference, but do not use it as a substitute for the required pre-exam system test and controlled network setup.
Decide what comes after the exam
Splunk lists Splunk Core Certified Advanced Power User, Splunk Enterprise Certified Admin, and Splunk Cloud Certified Admin as related next-step certifications. Choose a next path based on the type of work you want to do after consolidating Power User skills.
If your strongest interest is deeper searching and reporting, review the Advanced Power User direction. If your work is moving toward administration, compare the Enterprise and Cloud administration routes with the platform you support. The Power User exam’s field, data model, CIM, and reporting foundation can help make that choice more informed.
Certification maintenance also deserves a calendar note. Splunk says candidates can stay current by pursuing additional certifications, completing continuing education courses, or retaking a certification exam every three years. Check the official certification site before making renewal decisions because program requirements can change.
Your immediate next action is simpler: download or review the official blueprint, make a domain-by-domain skill inventory, choose authorized preparation resources for the gaps, and schedule only after confirming the delivery option and policy deadlines work for you. That sequence keeps study time tied to the actual assessed skills rather than to uncertain third-party exam labels.
Conclusion
The practical route to Splunk Core Certified Power User is to treat the blueprint as a set of working decisions: shape results, manage fields, create reusable knowledge objects, correlate events appropriately, and understand data models and CIM. Confirm the current exam name in Pearson VUE, build hands-on evidence for every domain, and protect the appointment with early setup and deadline checks. That approach is more useful than trying to memorize disconnected commands or unofficial question material.