Looking for your active Pro access before showing Course Notes. This usually takes just a moment.
Course Notes preview
Unlock Pro for the full per-exam reference guide.
Preview one piece from each section. Pro includes every Course Notes section, summary, key point, common mistake, exam tip, related-question review, and PDF export.
Includes full Course Mode and Course Notes.
Section 1Splunk Basics (5%)Preview
More in this section
9 more key points in Pro version
4 more common mistakes in Pro version
2 more exam tips in Pro version
7 more related questions in Pro version
Summary
Know what Splunk does, which component performs each core role, how apps organize the user experience and knowledge objects, and where user preferences and navigation live. For this domain, distinguish platform function, app context, and role-based access.
Key Points
Indexer: processes and stores indexed data and participates in searches.
Common Mistakes
Choosing a deployment server when the scenario says 'distribute searches' or 'consolidate results.'
Exam Tips
Translate nouns into jobs: search head = search coordination, indexer = store/search data, forwarder = send data.
Section 2Basic Searching (22%)Preview
More in this section
17 more key points in Pro version
8 more common mistakes in Pro version
3 more exam tips in Pro version
41 more related questions in Pro version
Summary
This is the heaviest domain. Be fluent with base-search Boolean behavior, field-value constraints, rolling versus snapped time ranges, search-result views, the timeline, event controls, job management, and export rules.
Key Points
Adjacent terms in a base search imply `AND`: `timeout checkout` means both terms must match.
Common Mistakes
Using `OR` when both terms are required.
Exam Tips
Read time words literally: 'previous 60 minutes' = rolling; 'since the start of the hour/day' = snapped boundary.
Section 3Using Fields in Searches (20%)Preview
More in this section
16 more key points in Pro version
6 more common mistakes in Pro version
2 more exam tips in Pro version
37 more related questions in Pro version
Summary
Fields are searchable name-value pairs extracted or calculated from events. Know how field presence, multivalue data, field-value predicates, the Fields sidebar, and field-manipulation commands affect what remains available downstream.
Key Points
A field is a name-value pairing associated with an event; not every returned event must contain every field.
Common Mistakes
Assuming a field must exist in every returned event.
Exam Tips
Ask three questions: Does the requirement change the event set, the field value, or only the presentation?
Section 4Search Language Fundamentals (15%)Preview
More in this section
12 more key points in Pro version
6 more common mistakes in Pro version
2 more exam tips in Pro version
27 more related questions in Pro version
Summary
Understand how SPL flows through a pipeline and how the core commands in the blueprint affect data. Scope searches early, know Splunk search Boolean precedence, and predict what fields/results exist after each command.
Key Points
The pipe `|` passes the output of one search command to the next command.
Common Mistakes
Thinking the pipe merges a subsearch rather than passing results sequentially.
Exam Tips
After every pipe, mentally ask: 'What rows and fields exist now?'
Master exactly what `top`, `rare`, and `stats` produce. These commands answer different statistical questions and transform event-level data into summarized result rows.
Key Points
`top field` returns the most frequent values of a field.
Common Mistakes
Using `rare` for most-common values.
Exam Tips
Underline the question word: most = top; least = rare; aggregate/group = stats.
Section 6Creating Reports and Dashboards (12%)Preview
More in this section
12 more key points in Pro version
6 more common mistakes in Pro version
2 more exam tips in Pro version
21 more related questions in Pro version
Summary
Know the lifecycle from a useful search to a saved report and then to a dashboard visualization. Focus on result structure, saved-object reuse, Dashboard Studio identifiers/layouts, editing, and permissions.
Key Points
Use Save As > Report to turn a useful search into a named report object.
Common Mistakes
Assuming every raw-event search can immediately drive every chart.
Exam Tips
Separate three layers: search result shape, saved report object, dashboard presentation.
Section 7Creating and Using Lookups (6%)Preview
More in this section
13 more key points in Pro version
5 more common mistakes in Pro version
2 more exam tips in Pro version
9 more related questions in Pro version
Summary
Lookups enrich search results by matching an event field to external reference data. Know the difference between the lookup data, lookup definition, matching key, output fields, explicit `lookup` command, and automatic lookup configuration.
Key Points
A lookup adds contextual fields from an external table or configured lookup source to matching search results.
Section 8Creating Scheduled Reports and Alerts (5%)Preview
More in this section
10 more key points in Pro version
4 more common mistakes in Pro version
2 more exam tips in Pro version
7 more related questions in Pro version
Summary
Scheduled reports deliver saved-search results on a schedule; alerts evaluate search results against trigger conditions and can launch actions. Know scheduling, trigger conditions, throttling, actions, permissions, and how to review fired alerts.
Key Points
A scheduled report runs a saved search automatically at configured times and produces/delivers its results.
Common Mistakes
Calling every scheduled saved search an alert.
Exam Tips
Ask: 'Should something happen only when a condition is true?' If yes, think alert; if not, scheduled report.
Search catalog
Find a practice exam
Flexible search understands AI-901, ai901, ai 901, 901, ai, network plus, and saa c03.