Splunk Core Certified Power User

Splunk · SPLK-1002 · Associate

Splunk · Splunk Ecosystem

Splunk Core Certified Power User

SPLK-1002activeAssociate
Official Splunk source · splunk.com

SPLK-1002 · ● Active · Associate · Splunk


Exam facts

FieldValue
CostUSD $130
Duration60 minutes
Questions65 (all scored)
Passing~70% (approx. 45–46 questions correct)
FormatMultiple choice / Multiple response
DeliveryPearson VUE (OnVUE / proctored center)
LanguagesEnglish
Valid3 years
RenewalRetake exam or pass higher-level certification (SPLK-1003)
PrerequisitesSplunk Core Certified User (SPLK-1001) recommended
Released2022
RetiringN/A

Vendor source — Splunk Training ↗
Official exam guide — SPLK-1002 Exam Guide ↗
Exam objectives — SPLK-1002 Objectives ↗


About

The Splunk Core Certified Power User (SPLK-1002) certifies hands-on proficiency in intermediate Splunk Enterprise search, data transformation, knowledge object creation, and operational administration. Targeted at SIEM analysts, Splunk administrators, and power users building production searches and automating workflows. Launched in 2022 as the intermediate step in Splunk's three-tier certification path (SPLK-1001 → SPLK-1002 → SPLK-1003). Requires or strongly recommends prior SPLK-1001 certification.


Domain context — Observability / SIEM

Security information and event management (SIEM) and observability platforms that aggregate, index, and search machine-generated data at scale. Splunk is the market-leading vendor in this space.

Read full deep dive — Splunk Ecosystem →


Topics covered

  • Using Transforming Commands (10%)
  • Filtering and Formatting Results (10%)
  • Correlating Events (15%)
  • Knowledge Objects (10%)
  • Fields, Tags, and Event Types (15%)
  • Creating and Managing Macros and Workflow Actions (10%)
  • Creating Field Aliases and Calculated Fields (10%)
  • Creating Tags and Event Types (10%)
  • Using Lookups (5%)
  • Creating Data Models (5%)

Source: Splunk SPLK-1002 Exam Objectives ↗


Common skills at Observability / SIEM · Associate

Shared competencies for intermediate SIEM and log management roles.

  • Advanced search query construction and optimization
  • Log parsing, field extraction, and event correlation
  • Building and tuning detection rules and alerts
  • Knowledge base management and reusable search objects
  • Data model design and deployment
  • Dashboard and report creation for operational visibility
  • Incident response workflow automation

Recommended courses at Observability / SIEM · Associate

ProviderTitleCostURL
Splunk Education (Official)Power User Course (online or instructor-led)Free (with registration) / $299 ILT
Splunk EducationSplunk Fundamentals 2Free (online)
UdemySplunk Enterprise Power User (SPLK-1002)$15–$50
Splunk Test DriveHands-on Lab EnvironmentFree

Course-selection rule: The official Splunk Education Power User course is the primary path. Udemy instructors vary in quality; verify reviews and cert-specific coverage. Test Drive provides free hands-on practice without cost.


Practice exams

ProviderTitleCostURL
Splunk Education (Official)Sample Exam Questions (online)Free
WhizlabsSplunk SPLK-1002 Practice Test$19–$39

Note: Vendor-official practice questions are limited. Third-party practice exam availability for SPLK-1002 is sparse compared to major cloud platforms; prioritize hands-on labs in Splunk Test Drive for practical validation.


Books

TitleAuthorPublisherYearISBNURL
Splunk Fundamentals HandbookSplunk Inc.Splunk Press (online)2023N/A
Learning SplunkFred MassiPackt Publishing2021978-1801078619

Book rule: Dedicated SPLK-1002 study guide does not exist as a published physical book. The official Splunk Fundamentals Handbook and Learning Splunk (Massi, 2021) provide foundational and intermediate content. Most study material comes from Splunk's free online courses and documentation.


Typical job titles at Observability / SIEM · Associate

Splunk Power User · Splunk Administrator (Junior) · SIEM Analyst · Splunk Engineer (Entry–Mid) · Splunk Developer

(Job titles drawn from current job-board postings that list SPLK-1002 or equivalent Splunk intermediate skills as required or preferred.)


Salary

RegionRangeSource
USD$70,000–$95,000 (SIEM/Splunk roles requiring SPLK-1002)Glassdoor ↗ · Robert Half Salary Guide ↗ · Levels.fyi ↗
ZARR800,000–R1,200,000 (annual, Johannesburg/Cape Town tech)Pnet ↗ · CareerJunction ↗
GBP£50,000–£70,000 (London/UK tech hubs)IT Jobs Watch ↗ · Hays Tech Salary Report ↗

Salary rule: Data reflects intermediate SIEM analyst and Splunk specialist roles. USD ranges derived from aggregated Glassdoor postings for "Splunk Administrator" and "SIEM Analyst" in 2025–2026. ZAR data sourced from South African job boards for mid-level IT security and data roles. GBP from UK tech market surveys. Ranges may vary by geography, organization size, and experience level.


Skills validated

Competencies this exam specifically tests — distinct from broader domain skills.

  • Splunk search processing language (SPL) advanced syntax
  • Transforming commands (stats, chart, timechart, eval, where)
  • Filtering, field extraction, and event deduplication
  • Event correlation and relationship mapping
  • Knowledge objects: fields, tags, event types, field aliases
  • Macros and workflow actions for search automation
  • Calculated fields and custom field generation
  • Lookups (file-based, KV store, external data enrichment)
  • Data models and pivot table creation
  • Search performance tuning and optimization

Related certifications


Sources


Last verified: 2026-05-01
Parent ecosystem: Splunk Ecosystem
Parent domain: Observability / SIEM
Vendor overview: Splunk Vendor Overview

Rate this cert
Was this helpful?
Comments ()
0/2000