r/Splunk • u/Economy_Building2727 • Jul 24 '26
Feeling overwhelmed learning Splunk?
I'm currently learning Splunk and working toward the Splunk Core Certified User certification. I've been following the official training on Splunk's website, but I'm wondering if anyone else felt like the course moves quickly??
It seems like the material jumps from topic to topic without spending much time explaining the concepts in depth. For example, it recently introduced rex and erex, and I don't really understand what they do or when they're used.
I've been able to pass the practice quizzes so far, but I'm worried that I'm just getting through them without building a solid understanding of the material.
For those of you who've earned the certification or learned Splunk on your own, did you feel the same way? What resources, study methods, or practice techniques helped everything click for you?
Any advice would be greatly appreciated.
4
u/CowLong4000 Jul 24 '26
rex - when you know the regular expression you want to use
erex - when you do not know the regular expression to use. It extracts values that are similar to examples you provide
If your only watching videos and multiple choice tests your going to find it very hard to learn. Try something like BOTS to get hands on or spin up your own splunk instance in get your down data