SPLK-1002 · ● Active · Associate · Splunk
Exam facts
| Field | Value |
|---|---|
| Cost | USD $130 |
| Duration | 60 minutes |
| Questions | 65 (all scored) |
| Passing | ~70% (approx. 45–46 questions correct) |
| Format | Multiple choice / Multiple response |
| Delivery | Pearson VUE (OnVUE / proctored center) |
| Languages | English |
| Valid | 3 years |
| Renewal | Retake exam or pass higher-level certification (SPLK-1003) |
| Prerequisites | Splunk Core Certified User (SPLK-1001) recommended |
| Released | 2022 |
| Retiring | N/A |
Vendor source — Splunk Training ↗
Official exam guide — SPLK-1002 Exam Guide ↗
Exam objectives — SPLK-1002 Objectives ↗
About
The Splunk Core Certified Power User (SPLK-1002) certifies hands-on proficiency in intermediate Splunk Enterprise search, data transformation, knowledge object creation, and operational administration. Targeted at SIEM analysts, Splunk administrators, and power users building production searches and automating workflows. Launched in 2022 as the intermediate step in Splunk's three-tier certification path (SPLK-1001 → SPLK-1002 → SPLK-1003). Requires or strongly recommends prior SPLK-1001 certification.
Domain context — Observability / SIEM
Security information and event management (SIEM) and observability platforms that aggregate, index, and search machine-generated data at scale. Splunk is the market-leading vendor in this space.
Read full deep dive — Splunk Ecosystem →
Topics covered
- Using Transforming Commands (10%)
- Filtering and Formatting Results (10%)
- Correlating Events (15%)
- Knowledge Objects (10%)
- Fields, Tags, and Event Types (15%)
- Creating and Managing Macros and Workflow Actions (10%)
- Creating Field Aliases and Calculated Fields (10%)
- Creating Tags and Event Types (10%)
- Using Lookups (5%)
- Creating Data Models (5%)
Source: Splunk SPLK-1002 Exam Objectives ↗
Common skills at Observability / SIEM · Associate
Shared competencies for intermediate SIEM and log management roles.
- Advanced search query construction and optimization
- Log parsing, field extraction, and event correlation
- Building and tuning detection rules and alerts
- Knowledge base management and reusable search objects
- Data model design and deployment
- Dashboard and report creation for operational visibility
- Incident response workflow automation
Recommended courses at Observability / SIEM · Associate
| Provider | Title | Cost | URL |
|---|---|---|---|
| Splunk Education (Official) | Power User Course (online or instructor-led) | Free (with registration) / $299 ILT | ↗ |
| Splunk Education | Splunk Fundamentals 2 | Free (online) | ↗ |
| Udemy | Splunk Enterprise Power User (SPLK-1002) | $15–$50 | ↗ |
| Splunk Test Drive | Hands-on Lab Environment | Free | ↗ |
Course-selection rule: The official Splunk Education Power User course is the primary path. Udemy instructors vary in quality; verify reviews and cert-specific coverage. Test Drive provides free hands-on practice without cost.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| Splunk Education (Official) | Sample Exam Questions (online) | Free | ↗ |
| Whizlabs | Splunk SPLK-1002 Practice Test | $19–$39 | ↗ |
Note: Vendor-official practice questions are limited. Third-party practice exam availability for SPLK-1002 is sparse compared to major cloud platforms; prioritize hands-on labs in Splunk Test Drive for practical validation.
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| Splunk Fundamentals Handbook | Splunk Inc. | Splunk Press (online) | 2023 | N/A | ↗ |
| Learning Splunk | Fred Massi | Packt Publishing | 2021 | 978-1801078619 | ↗ |
Book rule: Dedicated SPLK-1002 study guide does not exist as a published physical book. The official Splunk Fundamentals Handbook and Learning Splunk (Massi, 2021) provide foundational and intermediate content. Most study material comes from Splunk's free online courses and documentation.
Typical job titles at Observability / SIEM · Associate
Splunk Power User · Splunk Administrator (Junior) · SIEM Analyst · Splunk Engineer (Entry–Mid) · Splunk Developer
(Job titles drawn from current job-board postings that list SPLK-1002 or equivalent Splunk intermediate skills as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $70,000–$95,000 (SIEM/Splunk roles requiring SPLK-1002) | Glassdoor ↗ · Robert Half Salary Guide ↗ · Levels.fyi ↗ |
| ZAR | R800,000–R1,200,000 (annual, Johannesburg/Cape Town tech) | Pnet ↗ · CareerJunction ↗ |
| GBP | £50,000–£70,000 (London/UK tech hubs) | IT Jobs Watch ↗ · Hays Tech Salary Report ↗ |
Salary rule: Data reflects intermediate SIEM analyst and Splunk specialist roles. USD ranges derived from aggregated Glassdoor postings for "Splunk Administrator" and "SIEM Analyst" in 2025–2026. ZAR data sourced from South African job boards for mid-level IT security and data roles. GBP from UK tech market surveys. Ranges may vary by geography, organization size, and experience level.
Skills validated
Competencies this exam specifically tests — distinct from broader domain skills.
- Splunk search processing language (SPL) advanced syntax
- Transforming commands (stats, chart, timechart, eval, where)
- Filtering, field extraction, and event deduplication
- Event correlation and relationship mapping
- Knowledge objects: fields, tags, event types, field aliases
- Macros and workflow actions for search automation
- Calculated fields and custom field generation
- Lookups (file-based, KV store, external data enrichment)
- Data models and pivot table creation
- Search performance tuning and optimization
Related certifications
- Prerequisites: Splunk Core Certified User (SPLK-1001) ↗
- Prerequisite for: Splunk Enterprise Admin Certified (SPLK-1003) ↗
- Stacks with: Splunk SPLK-1001 (foundation) + SPLK-1002 (intermediate) → SPLK-1003 (expert)
- Vendor overview: Splunk Vendor Overview ↗
Sources
- Splunk Training & Certification: https://www.splunk.com/en_us/training/certification/core-certified-power-user.html
- Splunk Exam Objectives: https://www.splunk.com/en_us/training/certification/core-certified-power-user.html
- Splunk Fundamentals 2 Course: https://www.splunk.com/en_us/training/courses/fundamentals-2.html
- Splunk Test Drive (Hands-on Lab): https://www.splunk.com/en_us/enterprise-readiness/free-trial.html
- Splunk Fundamentals Handbook: https://www.splunk.com/en_us/resources/fundamentals-handbook.html
- Learning Splunk (Massi, 2021): https://www.packtpub.com/product/learning-splunk/
- Glassdoor Salary Data: https://www.glassdoor.com/
- Robert Half Technology Salary Guide: https://www.roberthalf.com/
- Pnet (South Africa): https://www.pnet.co.za/
- CareerJunction (South Africa): https://www.careerjunction.co.za/
- IT Jobs Watch (UK): https://www.itjobswatch.co.uk/
Last verified: 2026-05-01
Parent ecosystem: Splunk Ecosystem
Parent domain: Observability / SIEM
Vendor overview: Splunk Vendor Overview