Skip to content

Intermediate Splunk training

Build on your foundation. Advance your search and reporting skills.

Continue beyond the basics with visualizations, eval, knowledge objects, rex and erex, tags, event types, macros, workflow actions, and other Power User concepts inside AbleU.

Intermediate course 2 hours of video 2 practice tests Power User preparation
Splunk Fundamentals 2 course artwork
Explore the complete course hub
Learning journey Power User skills Key concepts Preview and FAQs
Explore below ↓
Step 2 of 5

See where this course fits in the Ableversity Splunk learning path.

View path ↓

Your Splunk Learning Journey

Step 2 of 5: Splunk Fundamentals 2

Follow the recommended sequence from foundational searching through Power User skills, administration, and enterprise architecture.

You are here Step 2 of 5 · Splunk Fundamentals 2

The highlighted step shows where this page sits in the recommended curriculum. It does not represent individual account completion or restrict access to other courses.

ACE Credential Journey

Course milestones lead to Ableversity credentials

Ableversity credential marker for ACE Certified User
ACE Certified User Complete Splunk Fundamentals 1 and the required Ableversity assessment.
Ableversity credential marker for ACE Certified Power User
ACE Certified Power User Complete Splunk Fundamentals 2 and 3 plus the required Ableversity assessment.
Ableversity credential marker for ACE Certified Administrator
ACE Certified Administrator Complete Splunk Enterprise Administrator and the required Ableversity assessment.
Ableversity credential marker for ACE Enterprise Architect
ACE Enterprise Architect Complete Splunk Enterprise Architect and the required Ableversity assessment.

ACE credentials are issued solely by Ableversity. They are separate from official Splunk certifications and are not issued, sponsored, approved, or endorsed by Splunk LLC.

Intermediate courseBuilds on Splunk Fundamentals 1.
Hands-on learningApply search, reporting, and knowledge-object concepts.
Learn at your paceWork through 22 focused lectures at your pace.
Completion certificatePrepare for the third-party Power User exam.

Is This the Right Course?

A strong next step after Splunk Fundamentals 1

This course is designed for learners who know the interface and basic searches and are ready to build more reusable, analytical, and efficient Splunk workflows.

Completed Fundamentals 1Or have equivalent foundational Splunk experience.
Comfortable with basic searchesYou can navigate Splunk and run simple searches.
Want stronger visualizationsLearn to communicate results more effectively.
Ready for regex and knowledge objectsMove beyond one-time searches into reusable tools.
Preparing for Power UserUse the course as part of third-party certification preparation.

Skills You Will Build

Power User skills for deeper search and analysis

Build on Fundamentals 1 with visualizations, eval, knowledge objects, regular expressions, tags, event types, macros, workflow actions, and related Power User concepts.

Searching and Calculation

Build more capable searches and calculated results.

  • Eval and calculated fields
  • Search logic and transformations
  • Fields and result interpretation

Knowledge and Classification

Organize and reuse important Splunk logic.

  • Knowledge objects
  • Tags and event types
  • Reusable visualizations and reports

Extraction and Automation

Make investigations faster and more consistent.

  • Rex and erex
  • Macros
  • Workflow actions

Why These Skills Matter

Understand the concepts behind real Power User work

These explanations make the page useful as a learning reference while showing how each topic fits into practical Splunk work.

Eval

Create useful calculated fields

The eval command lets you create, transform, categorize, and compare fields inside search results. It is central to many real-world searches because it helps turn raw event values into information that analysts can interpret, visualize, and reuse.

Knowledge Objects

Turn useful work into reusable assets

Knowledge objects help teams preserve and reuse searches, fields, reports, tags, event types, and other analytical logic. They support consistency, collaboration, and easier maintenance across a Splunk environment.

Rex and Erex

Extract structure from event data

Field extraction allows analysts to identify important values within raw events. Rex provides direct regular-expression control, while erex can help generate extraction patterns from examples. These skills are valuable when the fields you need are not already available.

Tags and Event Types

Classify events for easier analysis

Tags and event types help organize events around meaningful concepts rather than requiring users to remember every underlying search condition. They make searches easier to understand, maintain, and share.

Macros

Reuse common search logic

Macros allow repeated SPL logic to be stored once and referenced in multiple searches. This can reduce errors, improve consistency, and make complex searches easier for teams to manage.

Workflow Actions

Connect search results to the next action

Workflow actions help users move from a Splunk result into another search, external tool, or investigation step. They can shorten response time by placing useful actions directly alongside relevant event data.

Course Preview

See the teaching style before you begin

Open the course preview in YouTube to review the teaching approach, instructor delivery, and level of detail before continuing into AbleU.

  • Clear explanations of Power User concepts
  • Practical demonstrations of searches and knowledge objects
  • A structured bridge toward advanced Splunk work

Included With the Course

Focused resources for Power User preparation

The layout automatically adjusts to the number of included items, so future course pages can use three, four, five, or six cards without breaking alignment.

2 hours

On-demand video

Work through 22 lectures at your own pace and revisit difficult topics as needed.

2

Practice tests

Measure your understanding of visualizations, eval, knowledge objects, regex, and related concepts.

1

Completion certificate

Document completion of the Ableversity course after meeting the course requirements.

Course Roadmap

A focused path through Power User concepts

The course includes one section, 22 lectures, and approximately 2 hours and 9 minutes of total instruction.

1

Review

Reconnect with the Fundamentals 1 foundation.

2

Visualizations

Present results through effective visual outputs.

3

Eval

Create and transform fields in search results.

4

Knowledge Objects

Build reusable objects for consistent analysis.

5

Regex and Classification

Use rex, erex, tags, and event types.

6

Macros and Actions

Improve efficiency with reusable searches and workflow actions.

Who This Course Is For

Designed for learners ready to move beyond the basics

Fundamentals 1 graduatesContinue from the recommended prerequisite.
Aspiring Power UsersDevelop deeper search and analysis skills.
Analysts and investigatorsUse Splunk more effectively in daily work.
Certification candidatesPrepare for the third-party Power User exam.
Working professionalsLearn on demand around work and other responsibilities.

What You Will Learn

Core skills covered in Fundamentals 2

  • Build and refine visualizations
  • Use eval to create calculated fields
  • Create and manage knowledge objects
  • Use rex, erex, tags, and event types
  • Build macros and workflow actions
2 hours On-demand video lessons
3 resources Downloadable materials
2 practice tests Knowledge checks
Completion certificate Issued by Ableversity

Your Instructor

Learn with Principal Instructor Hailie Shaw

Hailie builds on the Fundamentals 1 foundation and guides learners through Power User concepts including visualizations, eval, knowledge objects, field extraction, tags, event types, macros, and workflow actions.

This course is designed to support Power User skill development and certification preparation. Splunk certification exams are administered by third parties, and course completion does not guarantee a certification result.

Requirements

Splunk Fundamentals 1 is recommended

  • Complete Splunk Fundamentals 1 or have equivalent foundational Splunk experience.
  • Be comfortable navigating Splunk and running basic searches.
  • Use a computer or supported device with internet access.
  • Be prepared to practice visualizations, eval, knowledge objects, and search techniques.

Continue Your Journey

Continue from Power User skills into advanced Splunk learning

Continue through Fundamentals 2 and 3, Systems Administration, Data Administration, and architecture-focused training as your skills develop.

Quick Facts

Splunk Fundamentals 2 course summary

A concise, machine-readable overview for learners, search engines, and AI assistants.

CourseSplunk Fundamentals 2
DifficultyIntermediate
DurationApproximately 2 hours
Lectures22
PrerequisiteSplunk Fundamentals 1
InstructorHailie Shaw
Certification SupportCore Certified Power User
PlatformAbleU by Ableversity
Course information reviewed for the current Ableversity learning path in August 2026.

AI Answer Center

Frequently asked questions about Splunk Fundamentals 2

Direct answers to the questions learners commonly ask search engines and AI assistants.

What is Splunk Fundamentals 2?

Splunk Fundamentals 2 is an intermediate Ableversity course covering visualizations, eval, knowledge objects, rex and erex, tags, event types, macros, workflow actions, and related Power User skills.

Do I need Splunk Fundamentals 1 first?

Splunk Fundamentals 1 is the recommended prerequisite. Learners should already understand the Splunk interface and basic searching before beginning Fundamentals 2.

How long is the course?

The course includes approximately 2 hours and 9 minutes of instruction across 22 lectures.

Is Fundamentals 2 harder than Fundamentals 1?

Yes. Fundamentals 2 builds on the beginner foundation and introduces more advanced search, field extraction, reusable knowledge, and automation concepts.

What certification does the course support?

The course supports preparation for the third-party Splunk Core Certified Power User exam. Ableversity does not administer the exam and cannot guarantee an exam result.

Does the course include practice tests?

Yes. The course includes two practice tests.

Who teaches the course?

The course is taught by Ableversity Principal Instructor Hailie Shaw.

What will I learn about eval?

You will learn how eval creates and transforms fields, applies calculations, and supports clearer analytical results.

Does the course teach regular expressions?

Yes. The course includes rex and erex concepts for extracting fields from event data.

What are knowledge objects?

Knowledge objects are reusable Splunk assets such as fields, reports, tags, event types, and other objects that support consistent searching and analysis.

Can I skip directly to Fundamentals 2?

You can access the course, but learners without equivalent foundational experience may find it more effective to complete Splunk Fundamentals 1 first.

Is the course self-paced?

Yes. The on-demand course can be completed at the learner’s own pace through AbleU.

What comes after Fundamentals 2?

The recommended next step is Splunk Fundamentals 3, followed by Splunk Enterprise Administrator and Splunk Enterprise Architect.

Does Ableversity issue official Splunk certification?

No. Ableversity provides training and certification preparation. Official Splunk certification exams are administered by third parties.

How do I access the course?

Open AbleU at ableu.ableversity.com, create an account, and complete onboarding to view available learning options.

Next Recommended Course

Splunk Fundamentals 3

Continue into more advanced searching, analytics, acceleration, and data techniques.

Continue to Fundamentals 3

Start Learning

Open AbleU and begin Splunk Fundamentals 2

Create your account, complete onboarding, and continue to the learning options available through the AbleU platform.

Splunk, Splunk>, and related Splunk product names are trademarks or registered trademarks of Splunk LLC in the United States and other countries. Ableversity is an independent training provider and is not affiliated with, sponsored by, approved by, or endorsed by Splunk LLC.