I just completed the 4 day "Fundamentals II" splunk class, I have yet to take the certification that goes with this class but feel I can describe the class pretty well to give others an idea of what you can expect.
Class delivery is 100% online, delivered with a live trainer. In my instance the trainer was formerly an internal splunk developer and
REALLY knew this material inside and out. Instructor quality was top notch.
The class includes credentials to the splunk lab environment for the duration of the class, which is also populated with ~4 million events from their fictional company (Buttercup Games). The students are power users in this splunk app.
Each day was 4:30 hours of instruction, walk through and 2-3 labs. The educator does review labs (you save queries and output as reports or dashboards for this reason) and if they think you missed the mark they will ask you to re-do the lab in question. With that said on day 1 they do give you the complete class PDF and both of the lab manuals (one standard, one with answers). So you have to be lazy to screw up the labs....
Overall I would say I came out with way more knowledge than I went in with. Fundamentals II is where you learn some of the fun stuff, like workflows, automatically correlating events, and making searches dynamic (or triggered/based off from alerts and/or other searches).
Class topics:
- Using transforming commands for visualizations
- Filtering & Formatting SPL results
- Correlating events ("Transaction" command)
- Creating & Managing Custom Fields
- Field Aliases, Calculated fields
- Creating and using Macros
- Workflows (GET & POST)
- Creating data models/data model acceleration
- Implementing CIM add-on for normalization
- other things related to all of the above....
I will post an update once I take the "Power User" cert with my thoughts on that.
Edit: A tool to generate events for your Splunk lab:
https://splunkbase.splunk.com/app/1924/