Skip to content
CBT Nuggets
DemoBook a Demo

Course Curriculum

One skill is free to watch — no signup needed. The other 10 premium skills unlock for your whole team with a CBT Nuggets plan.

Free skill preview

Welcome to Splunk

Erik ChoronDuration: 44m11 videos1 virtual lab

Watch this complete skill free — the same trainer, videos, and labs your team gets with a plan.

Watch free skill
  • Welcome to SplunkFree44m · 11 videos · 1 lab
  • Premium skill.Managing Splunk1h 5m · 15 videos · 1 lab
  • Premium skill.Searching Basics52m · 14 videos · 1 lab
  • Premium skill.Expanding the search52m · 13 videos · 1 lab
  • Premium skill.Using Fields45m · 13 videos · 1 lab
  • Premium skill.Search Language Fundamentals57m · 14 videos · 1 lab
  • Premium skill.Practicing SPL Searches58m · 13 videos · 1 lab
  • Premium skill.Top, Rare and Stats Commands48m · 15 videos · 1 lab
  • Premium skill.Reports and Dashboards47m · 9 videos · 1 lab
  • Premium skill.Using Lookups45m · 11 videos · 1 lab
  • Premium skill.Scheduled Reports and Alerts47m · 12 videos · 1 lab
Want to browse the locked skills?
with no purchase required. Already have an account?

An account gets you the full catalog to browse, pre-assessments, quiz questions on free skills, and IT Trainerbot, with every answer citing its source video.

Certification

Splunk Core Certified User

Splunk Core Certified User is an entry-level certification for demonstrating foundational understanding of Splunk Enterprise and Splunk Cloud. It validates the ability to navigate and use Splunk software, including searching, using fields and lookups...

Exam SPLK-1001Level Entry-levelDifficulty BeginnerCost $130
Perform searchesUse fields and lookupsCreate alertsCreate basic reportsCreate dashboardsSplunk Enterprise basics
Official certification page

Put this course to work for your team

Every plan includes this course plus the full library, virtual labs, and practice exams — or talk it through with sales.

For IT leaders

What IT leaders need to know before assigning this course

Security and operations teams often collect plenty of machine data but lack a consistent way to search it, interpret it, and turn it into useful SOC workflows. This 9.3-hour beginner course helps IT Directors standardize baseline Splunk skills for SOC analysts, security analysts, SIEM users, and IT operations staff who need to work with logs, fields, searches, reports, dashboards, lookups, scheduled reports, and alerts.

The course is a practical fit for teams adopting Splunk or expanding usage from basic navigation into repeatable searches and reporting. It also supports risk and compliance work by teaching teams how to search organizational data, identify reporting hosts, and understand Splunk’s role across SIEM/SOAR-style implementations. For change management, the course reinforces that Splunk should fit the organization’s existing monitoring stack — not create redundant tools or unclear ownership.

CBT Nuggets supports rollout with isolated Virtual Labs for safe Splunk practice, plus Playlists and Team Reporting to assign the course and monitor progress across the team.

Team Impact

How this training helps your team succeed

IT teams complete this training to make Splunk usage more consistent across SOC and operations workflows. The course uses an isolated lab with realistic data from multiple system types, so practitioners can practice searches without affecting production environments.

  • Improve SOC triage: Analysts practice narrowing events by fields such as host, helping distinguish repeated events from the number of systems reporting.
  • Support compliance investigations: Teams learn to search organizational data and interpret results in the context of security monitoring and compliance checks.
  • Clarify operational ownership: The course shows how Splunk administrators can share tasks, such as AWS log parsing or Cisco firewall review, with users.
  • Turn searches into action: Teams build toward reports, dashboards, lookups, scheduled reports, and alerts that make recurring analysis easier to repeat.

After completion

Capabilities your team walks away with

Knowledge

  • Splunk’s role in security monitoring, including where SIEM and SOAR concepts overlap.
  • How Splunk navigation, bookmarks, shared administrator tasks, and basic management areas support daily work.
  • How indexes, hosts, events, fields, and data sources affect search results.
  • Core SPL concepts, including expanding searches and using fields to refine results.
  • How commands such as top, rare, and stats summarize data for analysis.
  • How reports, dashboards, lookups, scheduled reports, and alerts fit into Splunk workflows.

Ability

  • Navigate a Splunk environment and work from a shared lab baseline.
  • Search across organizational data and interpret event counts versus reporting hosts.
  • Use selected fields to focus investigations and clean up result views.
  • Write foundational SPL searches and practice them against realistic log data.
  • Build reusable reporting outputs with dashboards, lookups, scheduled reports, and alerts.
  • Apply Splunk skills safely in an isolated lab before using them in production workflows.

Readiness check

Confirm prerequisite knowledge before training begins

A short placement assessment on the CBT Nuggets assessments platform measures whether a learner already has the foundation this course assumes. IT Directors use it to put the right people in the right training — and any learner can take it right now to make sure they'll get full value from day one.

  • Questions generated from this course's own video transcripts — what gets measured is exactly what gets taught
  • Instant, per-learner results that show whether the prerequisite foundation is in place
  • Results roll up into team readiness reporting, so training hours go where they change outcomes
Runs on assessments.cbtnuggets.com — sign in with an Adept account so results roll up into team readiness reporting. Need one?
.

This course is included with every subscription

Unlock this one course, or get one learner — or your whole team — access to all 287 courses, virtual labs, and practice exams.

Course Unlock

Just need this course?

$225one time

No subscription

One year of access to Splunk Core Certified User

  • Every skill in this course
  • Its virtual labs and practice exam
  • Ask IT Trainerbot about it — free

CBT Nuggets Individual

IT Trainerbot Pro

$49per month

Billed annually

Every course, for one learner

See Individual pricing
For IT teams

CBT Nuggets Teams

IT Trainerbot for Teams

$59per seat / mo

Billed annually

From 1 learner seat · unlimited admin seats

Checking your access

Need tenant hosting, reseller terms, or payment plans on a larger agreement? Book a Demo to discuss an Enterprise contract.

See plans and pricing for your team

Trusted by 23,000+ organizations

Ready to upskill your team?

Talk to our sales team to find the right plan for your organization.