Cheat sheet

Splunk Core Certified Power User Cheat Sheet

Using Transforming Commands for Visualizations

5%of exam

Filtering and Formatting Results

10%of exam

Correlating Events

15%of exam

Creating and Managing Fields

10%of exam

Field ExtractionRegex vs DelimiterField Extractorsourcetype

Creating Field Aliases and Calculated Fields

10%of exam

Creating Tags and Event Types

10%of exam

Creating and Using Macros

10%of exam

Creating and Using Workflow Actions

10%of exam

Creating Data Models

10%of exam

Using the Common Information Model Add-On

10%of exam

Quick Facts

Exam
Splunk Core Certified Power User
Questions
65 multiple-choice
Total time
60 minutes
Agreement
3 minutes within total
Prerequisite exam
None
Largest domain
Correlating Events: 15%
Passing cut score
Not published
Delivery
Pearson VUE

Chart vs Timechart

chart

  • Categorical row axis
  • Optional column split
  • Aggregation required

timechart

  • Time on x-axis
  • Optional series split
  • Aggregation required

Category axis vs time axis

Visualization Commands

chart
Aggregate by categorical axes
chart count OVER host
Host rows, count values
chart count OVER host BY status
Host rows; status columns
timechart
Aggregate by time buckets
timechart span=1h
Hourly buckets
timechart BY host
Host series across time

Search vs Where

search

  • Search expression syntax
  • Field=literal filtering

where

  • Boolean eval expression
  • Field-to-field comparison

Search terms vs eval predicates

Filtering and Formatting

eval
Compute result field
search
Filter by search syntax
where
Filter by Boolean eval
where a=b
Compare field values
where a="b"
Compare field with literal
fillnull
Replace eligible null values
fillnull value=0
Zero for eligible nulls
No field list
Needs schema-present fields
fillnull value=0 missing
Explicit list creates missing field

Transaction Clock

Span bounds whole; pause bounds gaps

maxspan: full durationmaxpause: adjacent eventsSort newest first

Transaction vs Stats

transaction

  • Groups raw related events
  • Duration and eventcount
  • Can use start/end rules

stats

  • Computes grouped aggregates
  • Usually more efficient
  • No raw transaction bundle

Event relationship vs aggregate

Correlation Picker

  1. Need aggregates by user→stats BY user(No raw grouping)
  2. Need grouped raw events→transaction user(Preserves event relationship)
  3. Bound full session→maxspan(Earliest-to-latest window)
  4. Bound adjacent gap→maxpause(Consecutive event interval)
  5. Manually sorted before transaction→sort 0 -_time(All events; consider sorting cost)
  6. Count grouped events→eventcount(Transaction output field)

Transaction Controls

transaction user
Group matching user events
maxspan
Limit total transaction span
maxpause
Limit adjacent-event gap
sort 0 -_time
All events, newest first
duration
Earliest-to-latest seconds
eventcount
Events grouped per transaction
startswith
Start-event condition
endswith
End-event condition
stats BY user
Aggregates without raw grouping

Regex vs Delimiter

Regex

  • Variable event patterns
  • Capture named values

Delimiter

  • Consistent column separator
  • Rename extracted columns

Pattern matching vs splitting

Field Extraction

Field Extractor
Create search-time extraction
Regex method
Variable unstructured patterns
Delimiter method
Consistently separated columns
Sample event
Preview candidate fields
False positives
Validate across representative events
Scope
Source or sourcetype association

Knowledge Object Sequence

Extract, alias, calculate, lookup, classify, tag

Extract sourceAlias nameCalculate valueLookup enrichmentEvent typeTag last

Alias vs Calculation

Field alias

  • Alternate existing name
  • Runs before calculations

Calculated field

  • Derives value with eval
  • Runs before lookups

Rename access vs derive value

Knowledge Object Picker

  1. Raw value not yet extracted→Field extraction(Regex or delimiter)
  2. Need alternate field name→Field alias(Source already exists)
  3. Need computed reusable value→Calculated field(Uses earlier fields)
  4. Need external enrichment→Lookup(Runs after calculations)
  5. Need named event class→Event type(Saved search condition)
  6. Need field-value category→Tag(Runs after event types)

Aliases and Calculations

Field alias
Copy existing field under alias
Calculated field
Search-time eval expression
FIELDALIAS-*
props.conf alias class
EVAL-*
props.conf calculated field
Alias input
Indexed or extracted field
Calculated input
Previously available field
Later lookup
Unavailable to calculated field

Search-Time Order

Extract
Make source fields available
Alias
Copy alternate field name
Calculate
Derive field with eval
Lookup
Enrich after calculations
Event type
Classify matching events
Tag
Label field-value pairs

Tag vs Event Type

Tag

  • Labels field-value pairs
  • Can label event types

Event type

  • Names matching event search
  • Evaluated before tags

Label vs event classification

Tags and Event Types

Event type
Named event-search definition
eventtype=login
Search named event classification
Tag
Label field-value pair
tag=authentication
Search tagged events
tags.conf
Configure tag assignments
eventtypes.conf
Configure event-type searches
Processing
Event types precede tags

Macro Call

Backticks expand; double quotes block

`name` expandsQuoted macro stays textEscape quoted arguments

Macro vs Event Type

Macro

  • Expands reusable SPL text
  • Arguments substitute variables

Event type

  • Classifies matching events
  • Search definition is saved

Text expansion vs classification

Macro Syntax

Macro
Reusable SPL text expansion
`name`
Invoke without arguments
`name(x)`
Invoke with argument
$arg$
Definition substitution variable
Backticks
Delimit macro invocation
Quoted macro text
Does not expand
Quoted argument
Escape embedded quote
Validation
Reject unsuitable arguments

Workflow Methods

GET opens, POST sends, Search pivots

GET: URLPOST: requestSearch: Splunk results

Workflow Picker

  1. Open external page→GET action(Parameterized URL)
  2. Submit external form→POST action(HTTP request body)
  3. Investigate related Splunk events→Search action(Secondary search)
  4. Send current event value→Field token(Configure context)
  5. Show only on matching fields→Field match rule(Scope action visibility)
  6. Handle untrusted event values→Review target exposure(Protect sensitive data)

Workflow Actions

GET
Open parameterized URL
POST
Submit HTTP request
Search
Launch secondary Splunk search
Event context
Pass selected field values
Field menu
Action appears on matching fields
URI
External target for GET/POST

Model vs Pivot

Data model

  • Defines reusable datasets
  • Provides selected attributes

Pivot

  • Builds reports from models
  • Visual interface for analysis

Data contract vs report builder

Data Models and Pivot

Data model
Reusable dataset hierarchy
Root dataset
Base event/search/transaction definition
Child dataset
Narrow inherited results
Attributes
Fields selectable or hidden in Pivot
Pivot
Reports without hand-written SPL
Transaction dataset
Relates events within model
Acceleration
Optional supported-dataset summaries

CIM Fields vs Tags

Fields

  • Standard names and meanings
  • Comparable values across sources

Tags

  • Classify relevant event types
  • Constrain model datasets

Shape values vs select events

CIM Mapping Picker

  1. Value exists only in raw→Extract field(Create source field)
  2. Different equivalent name→Field alias(Match CIM name)
  3. Expected value differs→Lookup or calculation(Match CIM semantics)
  4. Events lack model classification→Event type and tags(Match dataset constraints)
  5. Dashboard misses source→Inspect tags and fields(Validate included events)
  6. Model needs consistent reports→Pivot or model search(Use normalized dataset)

CIM Normalization

CIM
Shared normalized data models
CIM Add-On
Common models and knowledge objects
Field names
Map equivalent source fields
Field values
Normalize expected value semantics
Event types
Select matching event classes
Tags
Constrain relevant model events
Lookups
Supply or standardize values
Validation
Check model coverage and events

Common Traps

fillnull Field Selection

No field list: requires schema ≠ Explicit list: can create fields

Transaction ordering

Descending _time supports time limits ≠ Ascending _time can misgroup

Macro expansion

Backticked macro expands ≠ Quoted macro remains literal

Alias timing

Alias extracted field ≠ Cannot alias later lookup field

Calculation timing

Calculate from earlier fields ≠ Cannot depend on later lookup

Calculated field chaining

Same-stanza EVAL runs in parallel ≠ Do not chain calculated fields

Event type timing

Event type precedes tags ≠ Tag-dependent definition fails

CIM compliance

Match fields, values, tags ≠ Matching names alone insufficient

Transformation outputs

chart aggregates categories ≠ timechart buckets by time

Transaction cost

stats suits aggregate-only question ≠ transaction retains grouped raw events

Last Minute

  1. 1.65 questions; 60 minutes includes agreement
  2. 2.Correlating Events 15%; Visualizations 5%
  3. 3.Other eight blueprint domains: 10% each
  4. 4.chart categories; timechart time buckets
  5. 5.where compares fields; search filters terms
  6. 6.fillnull: explicitly name wholly absent fields
  7. 7.transaction time limits need descending _time
  8. 8.maxspan whole transaction; maxpause adjacent gap
  9. 9.stats aggregates; transaction retains related events
  10. 10.Extract before alias; calculate before lookup
  11. 11.Event types precede tags
  12. 12.Backticks expand macros; quotes prevent expansion
  13. 13.GET opens; POST submits; Search pivots
  14. 14.CIM needs matching fields, values, tags
Same family resources

Explore More Splunk Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.