Description
This next-level certification exam is a 57-minute, 65-question assessment which evaluates a candidate’s knowledge and skills of field aliases and calculated fields, creating tags and event types, using macros, creating workflow actions and data models, and normalizing data with the CIM.
Candidates can expect an additional 3 minutes to review the exam agreement, for a total seat time of 60 minutes.
In order to be prepared for the certification exam, Splunk recommends completing the following courses:
❏ Working with Time
❏ Statistical Processing
❏ Comparing Values
❏ Result Modification
❏ Correlation Analysis
❏ Creating Knowledge Objects
❏ Creating Field Extractions
❏ Data Models