Skip to main content
← Back to certifications
SplunkCybersecurityFoundationalVendor-specificActive

Splunk Core Certified User

An introductory Splunk credential for learners building skills in searching, filtering, using fields, creating basic reports, and working with data in the Splunk platform.

Last verified: 2026-09-01

Overview

Splunk Core Certified User is an entry-level credential validating fundamental skills in Splunk Enterprise and Splunk Cloud. It covers navigating Splunk, running and refining searches, working with fields, using core search commands, building reports and dashboards, using lookups, and creating scheduled reports and alerts. It is designed for new Splunk users, analysts, career changers, and technical professionals who need to demonstrate basic platform proficiency.

Recommended experience
Splunk lists no prerequisites. The credential is designed for candidates with little to no prior Splunk experience, although hands-on practice searching data, using fields, creating reports and dashboards, and working with lookups and alerts is recommended.
Estimated study time
30–60 hours
Target job roles
Splunk UserData AnalystSOC AnalystIT Operations AnalystSecurity Analyst

Exam Details

Splunk Core Certified User Exam

Exam code
Verify with official provider.
Number of exams
1
Duration
60 minutes
Question count
60 multiple-choice questions
Delivery method
Pearson VUE testing center or online delivery where available
Price
$130 USD per exam attempt

Skills and Domains

Splunk Basics

5%

Understand Splunk components, uses, apps, user settings, and basic navigation.

Basic Searching

22%

Run, refine, control, and save searches and work with time ranges, results, and events.

Using Fields in Searches

20%

Understand fields and use fields and the fields sidebar during searches.

Search Language Fundamentals

15%

Use core search practices, the search pipeline, indexes, and basic search commands.

Using Basic Transforming Commands

15%

Use top, rare, and stats to transform and summarize search results.

Creating Reports and Dashboards

12%

Create and edit reports, visualizations, and dashboards from searches.

Creating and Using Lookups

6%

Create lookup files and definitions, configure automatic lookups, and use them in searches.

Creating Scheduled Reports and Alerts

5%

Configure scheduled reports and create, manage, and review alerts.

Study Resources

Splunk Core Certified User Test Blueprint

Official resource

Official Guide · Free

Official exam blueprint with current domain weights.

View resource

Splunk Core Certified User

Official resource

Documentation · Free

Official Splunk certification page with current exam details.

View resource

Splunk Training and Certification FAQ

Official resource

Documentation · Free

Official Splunk certification policies and recertification guidance.

View resource

Renewal

Validity period
3 years
Renewal method
Meet Splunk recertification requirements before expiration, including retaking the applicable certification exam within the allowed window or earning an eligible higher downstream certification.
Notes
Splunk states that certifications follow a three-year lifecycle from the date of the highest certification exam passed. If a certification lapses, current Splunk program rules apply for re-entry.

Recommended Before

Verify with official provider.

Recommended After

Verify with official provider.

Alternatives

Verify with official provider.

Specializations

Verify with official provider.

Explore certification categories

Browse focused certification guides by technology and career domain.