Intermediate Splunk training
Build on your foundation. Advance your search and reporting skills.
Continue beyond the basics with visualizations, eval, knowledge objects, rex and erex, tags, event types, macros, workflow actions, and other Power User concepts inside AbleU.
See where this course fits in the Ableversity Splunk learning path.
Your Splunk Learning Journey
Step 2 of 5: Splunk Fundamentals 2
Follow the recommended sequence from foundational searching through Power User skills, administration, and enterprise architecture.
Splunk Fundamentals 1
Learn the interface, foundational searches, fields, and search results.
View course 2 Current CourseSplunk Fundamentals 2
Develop eval, regex, visualizations, knowledge objects, macros, and workflow actions.
Reload this course 3Splunk Fundamentals 3
Advance your SPL, acceleration, JSON, data-model, and analytical skills.
View courseSplunk Enterprise Administrator
Learn deployment, licensing, users, roles, indexes, forwarders, parsing, data onboarding, monitoring, and operations.
View course 5Splunk Enterprise Architect
Explore distributed deployments, clustering, high availability, disaster recovery, and architecture planning.
View courseThe highlighted step shows where this page sits in the recommended curriculum. It does not represent individual account completion or restrict access to other courses.
ACE Credential Journey
Course milestones lead to Ableversity credentials
ACE credentials are issued solely by Ableversity. They are separate from official Splunk certifications and are not issued, sponsored, approved, or endorsed by Splunk LLC.
Is This the Right Course?
A strong next step after Splunk Fundamentals 1
This course is designed for learners who know the interface and basic searches and are ready to build more reusable, analytical, and efficient Splunk workflows.
Skills You Will Build
Power User skills for deeper search and analysis
Build on Fundamentals 1 with visualizations, eval, knowledge objects, regular expressions, tags, event types, macros, workflow actions, and related Power User concepts.
Searching and Calculation
Build more capable searches and calculated results.
- Eval and calculated fields
- Search logic and transformations
- Fields and result interpretation
Knowledge and Classification
Organize and reuse important Splunk logic.
- Knowledge objects
- Tags and event types
- Reusable visualizations and reports
Extraction and Automation
Make investigations faster and more consistent.
- Rex and erex
- Macros
- Workflow actions
Why These Skills Matter
Understand the concepts behind real Power User work
These explanations make the page useful as a learning reference while showing how each topic fits into practical Splunk work.
Create useful calculated fields
The eval command lets you create, transform, categorize, and compare fields inside search results. It is central to many real-world searches because it helps turn raw event values into information that analysts can interpret, visualize, and reuse.
Turn useful work into reusable assets
Knowledge objects help teams preserve and reuse searches, fields, reports, tags, event types, and other analytical logic. They support consistency, collaboration, and easier maintenance across a Splunk environment.
Extract structure from event data
Field extraction allows analysts to identify important values within raw events. Rex provides direct regular-expression control, while erex can help generate extraction patterns from examples. These skills are valuable when the fields you need are not already available.
Classify events for easier analysis
Tags and event types help organize events around meaningful concepts rather than requiring users to remember every underlying search condition. They make searches easier to understand, maintain, and share.
Reuse common search logic
Macros allow repeated SPL logic to be stored once and referenced in multiple searches. This can reduce errors, improve consistency, and make complex searches easier for teams to manage.
Connect search results to the next action
Workflow actions help users move from a Splunk result into another search, external tool, or investigation step. They can shorten response time by placing useful actions directly alongside relevant event data.
Course Preview
See the teaching style before you begin
Open the course preview in YouTube to review the teaching approach, instructor delivery, and level of detail before continuing into AbleU.
- Clear explanations of Power User concepts
- Practical demonstrations of searches and knowledge objects
- A structured bridge toward advanced Splunk work
Included With the Course
Focused resources for Power User preparation
The layout automatically adjusts to the number of included items, so future course pages can use three, four, five, or six cards without breaking alignment.
On-demand video
Work through 22 lectures at your own pace and revisit difficult topics as needed.
Practice tests
Measure your understanding of visualizations, eval, knowledge objects, regex, and related concepts.
Completion certificate
Document completion of the Ableversity course after meeting the course requirements.
Course Roadmap
A focused path through Power User concepts
The course includes one section, 22 lectures, and approximately 2 hours and 9 minutes of total instruction.
Review
Reconnect with the Fundamentals 1 foundation.
Visualizations
Present results through effective visual outputs.
Eval
Create and transform fields in search results.
Knowledge Objects
Build reusable objects for consistent analysis.
Regex and Classification
Use rex, erex, tags, and event types.
Macros and Actions
Improve efficiency with reusable searches and workflow actions.
Who This Course Is For
Designed for learners ready to move beyond the basics
What You Will Learn
Core skills covered in Fundamentals 2
- Build and refine visualizations
- Use eval to create calculated fields
- Create and manage knowledge objects
- Use rex, erex, tags, and event types
- Build macros and workflow actions
Your Instructor
Learn with Principal Instructor Hailie Shaw
Hailie builds on the Fundamentals 1 foundation and guides learners through Power User concepts including visualizations, eval, knowledge objects, field extraction, tags, event types, macros, and workflow actions.
Requirements
Splunk Fundamentals 1 is recommended
- Complete Splunk Fundamentals 1 or have equivalent foundational Splunk experience.
- Be comfortable navigating Splunk and running basic searches.
- Use a computer or supported device with internet access.
- Be prepared to practice visualizations, eval, knowledge objects, and search techniques.
Continue Your Journey
Continue from Power User skills into advanced Splunk learning
Continue through Fundamentals 2 and 3, Systems Administration, Data Administration, and architecture-focused training as your skills develop.
Quick Facts
Splunk Fundamentals 2 course summary
A concise, machine-readable overview for learners, search engines, and AI assistants.
AI Answer Center
Frequently asked questions about Splunk Fundamentals 2
Direct answers to the questions learners commonly ask search engines and AI assistants.
What is Splunk Fundamentals 2?
Splunk Fundamentals 2 is an intermediate Ableversity course covering visualizations, eval, knowledge objects, rex and erex, tags, event types, macros, workflow actions, and related Power User skills.
Do I need Splunk Fundamentals 1 first?
Splunk Fundamentals 1 is the recommended prerequisite. Learners should already understand the Splunk interface and basic searching before beginning Fundamentals 2.
How long is the course?
The course includes approximately 2 hours and 9 minutes of instruction across 22 lectures.
Is Fundamentals 2 harder than Fundamentals 1?
Yes. Fundamentals 2 builds on the beginner foundation and introduces more advanced search, field extraction, reusable knowledge, and automation concepts.
What certification does the course support?
The course supports preparation for the third-party Splunk Core Certified Power User exam. Ableversity does not administer the exam and cannot guarantee an exam result.
Does the course include practice tests?
Yes. The course includes two practice tests.
Who teaches the course?
The course is taught by Ableversity Principal Instructor Hailie Shaw.
What will I learn about eval?
You will learn how eval creates and transforms fields, applies calculations, and supports clearer analytical results.
Does the course teach regular expressions?
Yes. The course includes rex and erex concepts for extracting fields from event data.
What are knowledge objects?
Knowledge objects are reusable Splunk assets such as fields, reports, tags, event types, and other objects that support consistent searching and analysis.
Can I skip directly to Fundamentals 2?
You can access the course, but learners without equivalent foundational experience may find it more effective to complete Splunk Fundamentals 1 first.
Is the course self-paced?
Yes. The on-demand course can be completed at the learner’s own pace through AbleU.
What comes after Fundamentals 2?
The recommended next step is Splunk Fundamentals 3, followed by Splunk Enterprise Administrator and Splunk Enterprise Architect.
Does Ableversity issue official Splunk certification?
No. Ableversity provides training and certification preparation. Official Splunk certification exams are administered by third parties.
How do I access the course?
Open AbleU at ableu.ableversity.com, create an account, and complete onboarding to view available learning options.
Continue Reading
Key Splunk concepts connected to this course
These topic cards can link to future Ableversity knowledge-base articles as they are published.
Understanding eval
Learn why calculated fields are central to practical SPL.
Read the course explanation →Knowledge objects explained
See how reusable assets improve consistency and teamwork.
Read the course explanation →Rex versus erex
Understand two approaches to extracting fields from events.
Read the course explanation →Tags and event types
Organize data around concepts that matter to users.
Read the course explanation →Splunk macros
Reuse search logic and reduce repeated work.
Read the course explanation →Workflow actions
Connect search results directly to investigation steps.
Read the course explanation →Start Learning
Open AbleU and begin Splunk Fundamentals 2
Create your account, complete onboarding, and continue to the learning options available through the AbleU platform.