Splunk Core Certified User
An introductory Splunk credential for learners building skills in searching, filtering, using fields, creating basic reports, and working with data in the Splunk platform.
Last verified: 2026-09-01
Overview
Splunk Core Certified User is an entry-level credential validating fundamental skills in Splunk Enterprise and Splunk Cloud. It covers navigating Splunk, running and refining searches, working with fields, using core search commands, building reports and dashboards, using lookups, and creating scheduled reports and alerts. It is designed for new Splunk users, analysts, career changers, and technical professionals who need to demonstrate basic platform proficiency.
- Recommended experience
- Splunk lists no prerequisites. The credential is designed for candidates with little to no prior Splunk experience, although hands-on practice searching data, using fields, creating reports and dashboards, and working with lookups and alerts is recommended.
- Estimated study time
- 30–60 hours
- Target job roles
- Splunk UserData AnalystSOC AnalystIT Operations AnalystSecurity Analyst
Exam Details
Splunk Core Certified User Exam
- Exam code
- Verify with official provider.
- Number of exams
- 1
- Duration
- 60 minutes
- Question count
- 60 multiple-choice questions
- Delivery method
- Pearson VUE testing center or online delivery where available
- Price
- $130 USD per exam attempt
Skills and Domains
Splunk Basics
5%Understand Splunk components, uses, apps, user settings, and basic navigation.
Basic Searching
22%Run, refine, control, and save searches and work with time ranges, results, and events.
Using Fields in Searches
20%Understand fields and use fields and the fields sidebar during searches.
Search Language Fundamentals
15%Use core search practices, the search pipeline, indexes, and basic search commands.
Using Basic Transforming Commands
15%Use top, rare, and stats to transform and summarize search results.
Creating Reports and Dashboards
12%Create and edit reports, visualizations, and dashboards from searches.
Creating and Using Lookups
6%Create lookup files and definitions, configure automatic lookups, and use them in searches.
Creating Scheduled Reports and Alerts
5%Configure scheduled reports and create, manage, and review alerts.
Study Resources
Splunk Core Certified User Test Blueprint
Official resourceOfficial Guide · Free
Official exam blueprint with current domain weights.
View resourceSplunk Core Certified User
Official resourceDocumentation · Free
Official Splunk certification page with current exam details.
View resourceSplunk Training and Certification FAQ
Official resourceDocumentation · Free
Official Splunk certification policies and recertification guidance.
View resourceRenewal
- Validity period
- 3 years
- Renewal method
- Meet Splunk recertification requirements before expiration, including retaking the applicable certification exam within the allowed window or earning an eligible higher downstream certification.
- Notes
- Splunk states that certifications follow a three-year lifecycle from the date of the highest certification exam passed. If a certification lapses, current Splunk program rules apply for re-entry.
Related Certifications
Recommended Before
Verify with official provider.
Recommended After
Verify with official provider.
Alternatives
Verify with official provider.
Specializations
Verify with official provider.
Keep exploring on ThirdBadge
Connect this certification to its broader technology area, career roadmaps, training, and study resources.
Explore certification categories
Browse focused certification guides by technology and career domain.