Using Transforming Commands for Visualizations
5%of exam
Filtering and Formatting Results
10%of exam
Correlating Events
15%of exam
Creating and Managing Fields
10%of exam
Creating Field Aliases and Calculated Fields
10%of exam
Creating Tags and Event Types
10%of exam
Creating and Using Macros
10%of exam
Creating and Using Workflow Actions
10%of exam
Creating Data Models
10%of exam
Using the Common Information Model Add-On
10%of exam
Quick Facts
- Exam
- Splunk Core Certified Power User
- Questions
- 65 multiple-choice
- Total time
- 60 minutes
- Agreement
- 3 minutes within total
- Prerequisite exam
- None
- Largest domain
- Correlating Events: 15%
- Passing cut score
- Not published
- Delivery
- Pearson VUE
Chart vs Timechart
chart
- Categorical row axis
- Optional column split
- Aggregation required
timechart
- Time on x-axis
- Optional series split
- Aggregation required
Category axis vs time axis
Visualization Commands
- chart
- Aggregate by categorical axes
- chart count OVER host
- Host rows, count values
- chart count OVER host BY status
- Host rows; status columns
- timechart
- Aggregate by time buckets
- timechart span=1h
- Hourly buckets
- timechart BY host
- Host series across time
Search vs Where
search
- Search expression syntax
- Field=literal filtering
where
- Boolean eval expression
- Field-to-field comparison
Search terms vs eval predicates
Filtering and Formatting
- eval
- Compute result field
- search
- Filter by search syntax
- where
- Filter by Boolean eval
- where a=b
- Compare field values
- where a="b"
- Compare field with literal
- fillnull
- Replace eligible null values
- fillnull value=0
- Zero for eligible nulls
- No field list
- Needs schema-present fields
- fillnull value=0 missing
- Explicit list creates missing field
Transaction Clock
Span bounds whole; pause bounds gaps
Transaction vs Stats
transaction
- Groups raw related events
- Duration and eventcount
- Can use start/end rules
stats
- Computes grouped aggregates
- Usually more efficient
- No raw transaction bundle
Event relationship vs aggregate
Correlation Picker
- Need aggregates by user→stats BY user(No raw grouping)
- Need grouped raw events→transaction user(Preserves event relationship)
- Bound full session→maxspan(Earliest-to-latest window)
- Bound adjacent gap→maxpause(Consecutive event interval)
- Manually sorted before transaction→sort 0 -_time(All events; consider sorting cost)
- Count grouped events→eventcount(Transaction output field)
Transaction Controls
- transaction user
- Group matching user events
- maxspan
- Limit total transaction span
- maxpause
- Limit adjacent-event gap
- sort 0 -_time
- All events, newest first
- duration
- Earliest-to-latest seconds
- eventcount
- Events grouped per transaction
- startswith
- Start-event condition
- endswith
- End-event condition
- stats BY user
- Aggregates without raw grouping
Regex vs Delimiter
Regex
- Variable event patterns
- Capture named values
Delimiter
- Consistent column separator
- Rename extracted columns
Pattern matching vs splitting
Field Extraction
- Field Extractor
- Create search-time extraction
- Regex method
- Variable unstructured patterns
- Delimiter method
- Consistently separated columns
- Sample event
- Preview candidate fields
- False positives
- Validate across representative events
- Scope
- Source or sourcetype association
Knowledge Object Sequence
Extract, alias, calculate, lookup, classify, tag
Alias vs Calculation
Field alias
- Alternate existing name
- Runs before calculations
Calculated field
- Derives value with eval
- Runs before lookups
Rename access vs derive value
Knowledge Object Picker
- Raw value not yet extracted→Field extraction(Regex or delimiter)
- Need alternate field name→Field alias(Source already exists)
- Need computed reusable value→Calculated field(Uses earlier fields)
- Need external enrichment→Lookup(Runs after calculations)
- Need named event class→Event type(Saved search condition)
- Need field-value category→Tag(Runs after event types)
Aliases and Calculations
- Field alias
- Copy existing field under alias
- Calculated field
- Search-time eval expression
- FIELDALIAS-*
- props.conf alias class
- EVAL-*
- props.conf calculated field
- Alias input
- Indexed or extracted field
- Calculated input
- Previously available field
- Later lookup
- Unavailable to calculated field
Search-Time Order
- Extract
- Make source fields available
- Alias
- Copy alternate field name
- Calculate
- Derive field with eval
- Lookup
- Enrich after calculations
- Event type
- Classify matching events
- Tag
- Label field-value pairs
Tag vs Event Type
Tag
- Labels field-value pairs
- Can label event types
Event type
- Names matching event search
- Evaluated before tags
Label vs event classification
Macro Call
Backticks expand; double quotes block
Macro vs Event Type
Macro
- Expands reusable SPL text
- Arguments substitute variables
Event type
- Classifies matching events
- Search definition is saved
Text expansion vs classification
Macro Syntax
- Macro
- Reusable SPL text expansion
- `name`
- Invoke without arguments
- `name(x)`
- Invoke with argument
- $arg$
- Definition substitution variable
- Backticks
- Delimit macro invocation
- Quoted macro text
- Does not expand
- Quoted argument
- Escape embedded quote
- Validation
- Reject unsuitable arguments
Workflow Methods
GET opens, POST sends, Search pivots
Workflow Picker
- Open external page→GET action(Parameterized URL)
- Submit external form→POST action(HTTP request body)
- Investigate related Splunk events→Search action(Secondary search)
- Send current event value→Field token(Configure context)
- Show only on matching fields→Field match rule(Scope action visibility)
- Handle untrusted event values→Review target exposure(Protect sensitive data)
Workflow Actions
- GET
- Open parameterized URL
- POST
- Submit HTTP request
- Search
- Launch secondary Splunk search
- Event context
- Pass selected field values
- Field menu
- Action appears on matching fields
- URI
- External target for GET/POST
Model vs Pivot
Data model
- Defines reusable datasets
- Provides selected attributes
Pivot
- Builds reports from models
- Visual interface for analysis
Data contract vs report builder
Data Models and Pivot
- Data model
- Reusable dataset hierarchy
- Root dataset
- Base event/search/transaction definition
- Child dataset
- Narrow inherited results
- Attributes
- Fields selectable or hidden in Pivot
- Pivot
- Reports without hand-written SPL
- Transaction dataset
- Relates events within model
- Acceleration
- Optional supported-dataset summaries
CIM Mapping Picker
- Value exists only in raw→Extract field(Create source field)
- Different equivalent name→Field alias(Match CIM name)
- Expected value differs→Lookup or calculation(Match CIM semantics)
- Events lack model classification→Event type and tags(Match dataset constraints)
- Dashboard misses source→Inspect tags and fields(Validate included events)
- Model needs consistent reports→Pivot or model search(Use normalized dataset)
CIM Normalization
- CIM
- Shared normalized data models
- CIM Add-On
- Common models and knowledge objects
- Field names
- Map equivalent source fields
- Field values
- Normalize expected value semantics
- Event types
- Select matching event classes
- Tags
- Constrain relevant model events
- Lookups
- Supply or standardize values
- Validation
- Check model coverage and events
Common Traps
fillnull Field Selection
No field list: requires schema ≠ Explicit list: can create fields
Transaction ordering
Descending _time supports time limits ≠ Ascending _time can misgroup
Macro expansion
Backticked macro expands ≠ Quoted macro remains literal
Alias timing
Alias extracted field ≠ Cannot alias later lookup field
Calculation timing
Calculate from earlier fields ≠ Cannot depend on later lookup
Calculated field chaining
Same-stanza EVAL runs in parallel ≠ Do not chain calculated fields
Event type timing
Event type precedes tags ≠ Tag-dependent definition fails
CIM compliance
Match fields, values, tags ≠ Matching names alone insufficient
Transformation outputs
chart aggregates categories ≠ timechart buckets by time
Transaction cost
stats suits aggregate-only question ≠ transaction retains grouped raw events
Last Minute
- 1.65 questions; 60 minutes includes agreement
- 2.Correlating Events 15%; Visualizations 5%
- 3.Other eight blueprint domains: 10% each
- 4.chart categories; timechart time buckets
- 5.where compares fields; search filters terms
- 6.fillnull: explicitly name wholly absent fields
- 7.transaction time limits need descending _time
- 8.maxspan whole transaction; maxpause adjacent gap
- 9.stats aggregates; transaction retains related events
- 10.Extract before alias; calculate before lookup
- 11.Event types precede tags
- 12.Backticks expand macros; quotes prevent expansion
- 13.GET opens; POST submits; Search pivots
- 14.CIM needs matching fields, values, tags
Explore More Splunk Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
