The Splunk Core Certified Power User exam is the gateway to the rest of the Splunk certification track — it is a stated prerequisite for Enterprise Admin. It is also the exam most commonly misdescribed online, on two points that matter before you book it.
Every figure below comes from Splunk’s own certification pages, checked on 12 September 2026. Where Splunk publishes nothing, we say so instead of repeating a number we cannot source.

The exam at a glance
| Item | Verified detail |
|---|---|
| Official name | Splunk Core Certified Power User |
| Commonly used code | SPLK-1002 |
| Questions | 65, multiple choice |
| Time limit | 60 minutes |
| Cost | USD $130 per attempt |
| Prerequisites | None |
| Recertification | Every three years |
| Passing score | Not published by Splunk |
Myth one: you do not need Core Certified User first
Splunk lists the prerequisites for Power User as none. You can book this exam as your first Splunk certification.
This matters because a great many study plans and comparison pages present Splunk Core Certified User as a required first step. It is a genuine certification and a reasonable place to start if you are entirely new to the platform — but it is not a gate. If you already work with Splunk searches day to day, you can go straight to Power User and save yourself $130 and several weeks.
Myth two: the “entry-level” exam gives you less time, not more
Power User asks 65 questions in 60 minutes. That is roughly 55 seconds per question.
The Enterprise Admin exam, which sits above it and requires this certification first, asks 56 questions in the same 60 minutes — about 64 seconds each. So the earlier exam in the track is the more time-pressured of the two, by nine seconds a question.

Nine seconds sounds trivial. Across a full paper it is the difference between finishing with time to revisit flagged questions and running out with five unanswered. Candidates who fail this exam more often run out of time than run out of knowledge.
The practical consequence: practise under a timer from your first session, not your last week. If you cannot answer a question about a field alias or a macro in under a minute without deriving it from scratch, you do not yet know it well enough for this format.
Practise under real SPLK-1002 exam conditions
Timed to the real 65-question, 60-minute format, with a written explanation for every answer — so the questions you get wrong are the ones you learn from.
- Full-length timed tests matching the 65-question, 60-minute format
- An explanation for every answer, right and wrong
- Original questions written from Splunk’s published blueprint — never real exam content
On Udemy · lifetime access · 30-day refund policy applies
Going on to Admin next? Enterprise Admin practice tests. Planning further ahead? Architect practice tests.
On the passing score
Splunk does not publish one. You will find 70% and 75% asserted confidently in plenty of places, with no source behind either.
Rather than aim at an unverifiable threshold, aim to score consistently in the mid-eighties on realistic timed practice. At that level the exact cut score stops mattering. And treat any page that states the number as fact as a page worth double-checking on everything else.
What the exam covers
Splunk describes Power User as expanding basic Splunk skills into searching and reporting, and the creation of objects. Specifically named on the certification page:
- Searching and reporting
- Knowledge objects, tags and event types
- Workflow actions
- Data models
- Field aliases and calculated fields
- Macros
- Normalising data for Splunk
Note what is absent: domain percentage weightings. Those live in Splunk’s downloadable test blueprint, not on the public pages, so we do not quote them. Download the blueprint from Splunk’s certification track page and treat it as your syllabus of record.
Where candidates typically lose marks is the knowledge-object family — field aliases, calculated fields and macros. Each is individually simple, which is exactly why they get skimmed. The exam tends to test which one applies in a given situation and the order in which they are applied, and that distinction is hard to reason out in 55 seconds.
Is it worth taking?
Two honest reasons to sit it.
It is the only route to the Enterprise Admin certification, so if the Admin badge is your target, this is not optional. Budget $260 for both exams before any retake.
And it validates the skills people actually use in a Splunk role — building knowledge objects and data models rather than just running searches. That makes it more meaningful on a CV than the entry-level certification below it.
One reason to wait: if you have never used Splunk at all, spend a few weeks in a real instance before booking. This exam rewards familiarity, and 55 seconds a question punishes anyone still thinking in first principles.
A sane preparation approach
- Download the official test blueprint and use it as your checklist — it is the only authoritative statement of scope.
- Get hands on an instance. Build a field alias, a calculated field and a macro yourself; the differences stop being abstract immediately.
- Practise under a timer at roughly 55 seconds a question, from the start.
- Track which topics you get wrong, not just your overall score. A 78% concentrated in data models needs different work than a 78% spread evenly.
- Only book the exam once your timed scores are consistently in the mid-eighties.
Where practice questions fit
Practice questions do two jobs: they build the pace this exam demands, and they surface gaps you do not know you have. They are not a replacement for the blueprint or for hands-on time.
A caution on sourcing. Many results for this exam are “dump” sites claiming to host real exam content. Using them breaches Splunk’s exam agreement and puts the certification you are working towards at risk. Questions written from the published blueprint are a different thing, and the only kind worth your time.
Ready to practise against the clock?
Planning the full track? Our verified guide to the Splunk Enterprise Certified Admin exam covers the next step up.
Frequently asked questions
How many questions are on the Splunk Core Certified Power User exam?
65 multiple-choice questions, with a 60-minute time limit — roughly 55 seconds per question.
Do I need Splunk Core Certified User before Power User?
No. Splunk lists the prerequisites for Power User as none. You can take it as your first Splunk certification.
How much does the SPLK-1002 exam cost?
USD $130 per attempt, as listed on Splunk’s certification track page in September 2026.
What is the passing score?
Splunk does not publish one. Treat any specific figure you find online as unverified, and aim for consistent mid-eighties scores in timed practice instead.
Is Power User required for the Enterprise Admin certification?
Yes. Splunk lists Core Certified Power User as a prerequisite for Splunk Enterprise Certified Admin.
Sources. Splunk Core Certified Power User certification track page and Splunk certification overview — splunk.com, accessed 12 September 2026. Per-question timings are our own calculation from the published question counts and durations. Exam parameters change; if you spot a discrepancy, check Splunk’s page and tell us so we can correct it.
Disclosure and disclaimer. FoxMedium publishes independent study material. Our practice tests are not official Splunk content and are not endorsed by, affiliated with, or representative of Splunk, Cisco, or the official certification examination. All questions are original and written from publicly published exam blueprints. We do not host or distribute real exam content. Links to our courses earn us revenue if you enrol. Splunk and all related trademarks belong to their respective owners.

