1.1 Current Exam Facts & Logistics

Key Takeaways

  • The Splunk Core Certified User exam has 60 multiple-choice questions and 60 minutes total seat time (57 minutes testing plus 3 minutes for the exam agreement).
  • The exam fee is $130 USD per attempt through Pearson VUE, and there are no prerequisite exams.
  • Splunk does not publish a numeric passing score for User — results are pass/fail only.
  • Retake waits are 7 days after a first fail and 14 days after a second fail; User recertification is by retaking User or earning Power User.
Last updated: August 2026

What the Splunk Core Certified User exam is

Splunk Core Certified User is Splunk's entry-level certification for people who search, explore, and report on machine data inside a Splunk deployment. It is the User exam only — not Power User, not Admin, and not Enterprise Security. The official blueprint is published by Splunk as the Splunk Test Blueprint – User PDF. That document is the syllabus source of truth for this study guide.

This credential proves you can navigate the Search & Reporting app, run and refine searches, work with fields, use fundamental SPL commands, create basic transforming stats, save reports and dashboards, apply lookups, and schedule simple reports and alerts. It does not require you to design data models, manage indexes as an admin, or master Power User topics such as macros, tags, event types, or CIM mapping.

Official logistics you must memorize

Use these numbers exactly. Third-party blogs sometimes list stale figures (for example 55 questions). Do not rely on those.

FactOfficial value
CredentialSplunk Core Certified User
Question count60 multiple-choice questions
Seat time60 minutes total — 57 minutes of testing + 3 minutes to review the exam agreement
Fee$130 USD per attempt (Pearson VUE)
Passing scoreNot published (pass/fail only)
PrerequisitesNone
LevelEntry-level

Exam trap: "60 minutes" means total seat time including the agreement screen, not 60 minutes of pure testing. If a practice quiz asks how long you have to answer questions, the testing window is 57 minutes within a 60-minute appointment.

Exam trap: Never invent a passing percentage such as 70% or 75%. Splunk reports User results as pass or fail without publishing a cut score in the blueprint.

Delivery, retakes, and recertification

You schedule and take the exam through Pearson VUE (online proctored or test center, depending on availability). Each paid attempt is $130 USD.

Retake policy (official):

  • After a first failure, wait 7 days before retaking.
  • After a second failure, wait 14 days before retaking.

Plan study blocks around those windows so a fail does not waste a calendar week of momentum.

Recertify at User level: Splunk's User path does not use continuing-education (CE) courses for User recertification. You either retake the User exam or earn Splunk Core Certified Power User. Do not study CE-credit workflows as if they apply to User — that is a common Power User / Admin confusion.

The eight blueprint domains (exact weights)

Every scored topic maps to one of these domains. Weight percentages tell you where to spend study hours — not where the "easy" questions live. A 5% domain can still fail you if you ignore it entirely, but a 22% domain should dominate practice time.

DomainTitleWeight
1.0Splunk Basics5%
2.0Basic Searching22%
3.0Using Fields in Searches20%
4.0Search Language Fundamentals15%
5.0Using Basic Transforming Commands15%
6.0Creating Reports and Dashboards12%
7.0Creating and Using Lookups6%
8.0Creating Scheduled Reports and Alerts5%

Add the weights: 5 + 22 + 20 + 15 + 15 + 12 + 6 + 5 = 100%. Domains 2.0 and 3.0 alone are 42% of the exam. Domains 4.0 and 5.0 add another 30%. Together, searching, fields, SPL fundamentals, and transforming commands are roughly three-quarters of the test. Basics, lookups, and scheduled reports/alerts are smaller but still required.

Blueprint topics at a glance

  • 1.0 Splunk Basics: components, uses of Splunk, apps, user settings, basic navigation.
  • 2.0 Basic Searching: run searches, time ranges, interpret results, refine, timeline, events, search jobs, save results.
  • 3.0 Using Fields in Searches: what fields are, using fields in searches, fields sidebar.
  • 4.0 Search Language Fundamentals: search practices, pipeline, indexes, table / rename / fields / dedup / sort.
  • 5.0 Basic Transforming Commands: top, rare, stats.
  • 6.0 Reports and Dashboards: save/edit reports, stats vs chart visualizations, create/edit dashboards, add reports to dashboards.
  • 7.0 Lookups: describe lookups, files, definitions, automatic lookups, use in searches.
  • 8.0 Scheduled Reports and Alerts: describe/configure scheduled reports; create alerts; view fired alerts.

Splunk notes that related topics may appear and that the guidelines can change without notice. Still, these eight domains are the checklist you should finish before exam day.

Suggested official learning path (non-exhaustive)

The blueprint lists Splunk training courses that commonly map to User topics: Intro to Splunk; Using Fields; Scheduling Reports and Alerts; Visualizations; Working with Time; Statistical Processing; Leveraging Lookups and Subsearches; Search Optimization. You can also use Splunk Docs and the Splunk How-To YouTube channel. Free OpenExamPrep practice plus this guide should sit alongside hands-on searching in a lab or free Splunk instance — memorizing terms without clicking the UI is a common fail pattern.

How to use logistics on exam day

  1. Confirm you registered for Splunk Core Certified User, not Power User.
  2. Budget the 3-minute agreement so you still have 57 minutes for 60 questions (~57 seconds per question average).
  3. Flag hard items and move on; time pressure is real at entry level when searches and field questions look similar.
  4. After the exam, if you fail, calendar the 7-day or 14-day retake wait immediately and retarget the weakest domains from the score report if provided.

Master these facts first. The rest of the guide teaches the skills the blueprint weights — starting with Splunk Basics at 5%, then the heavy search and fields domains.

Test Your Knowledge

How many multiple-choice questions are on the Splunk Core Certified User exam?

A
B
C
D
Test Your Knowledge

What is the total seat time for the Splunk Core Certified User exam appointment?

A
B
C
D
Test Your Knowledge

According to official User retake policy, how long must you wait after a first failed attempt before retaking?

A
B
C
D