Splunk Core Certified Power User Exam Test questions
A Splunk Core Certified Power User has a basic understanding of SPL searching, reporting commands can create knowledge objects, use field aliases and calculated fields, create tags and event types, use macros, create workflow actions and data models, and normalize data with the Common Information Model in either the Splunk Enterprise or Splunk Cloud platforms. This certification demonstrates an individual's foundational competence of Splunk’s core software.
Course Objectives
Module 1 - Introduction
Module 2 - Beyond Search Fundamentals
Module 3 - Using Transforming Commands for Visualizations
Explore data structure requirements
Explore visualization types
Create and format charts and timecharts
Module 4 - Using Mapping and Single Value Commands
The iplocation command
The geostats command
The geom command
The addtotals command
Module 5 - Filtering and Formatting Results
Module 6 - Correlating Events
Identify transactions
Group events using fields
Group events using fields and time
Search with transactions
Report on transactions
Determine when to use transactions vs. stats
Module 7 - Introduction to Knowledge Objects
Module 8 - Creating and Managing Fields
Module 9 - Creating Field Aliases and Calculated Fields
Describe, create, and use field aliases
Describe, create and use calculated fields
Module 10 - Creating Tags and Event Types
Module 11 - Creating and Using Macros
Describe macros
Create and use a basic macro
Define arguments and variables for a macro
Add and use arguments with a macro
Module 12 - Creating and Using Workflow Actions
Describe the function of GET, POST, and Search workflow
actions
Create a GET workflow action
Create a POST workflow action
Create a Search workflow action
Module 13 - Creating Data Models
Describe the relationship between data models and pivot
Identify data model attributes
Create a data model
Use a data model in pivot
Module 14 - Using the Common Information Model (CIM) Add-On