Exam objectives
Enterprise Certified AdminSplunk Enterprise Certified Admin exam objectives
The published blueprint is the contract: the exam can only test what is on this list. Domains carry their official weightings, and objectives with a practice page link straight to questions written for that objective.
Titles and weightings from the official objectives. Splunk exam page ↗
Splunk Admin Basics
5%of examLicense Management
5%of examSplunk Configuration Files
5%of exam- 3.1 Describe Splunk configuration directory structurePractice
3.2 Understand configuration layeringIn the bank
3.3 Understand configuration precedenceIn the bank
3.4 Use btool to examine configuration settingsIn the bank
Splunk Indexes
10%of exam4.1 Describe index structureIn the bank
4.2 List types of index bucketsIn the bank
4.3 Check index data integrityIn the bank
- 4.4 Describe indexes.conf optionsPractice
4.5 Describe the fishbucketIn the bank
4.6 Apply a data retention policyIn the bank
Splunk User Management
5%of exam- 5.1 Describe user roles in SplunkPractice
5.2 Create a custom roleIn the bank
5.3 Add Splunk usersIn the bank
Splunk Authentication Management
5%of exam6.1 Integrate Splunk with LDAPIn the bank
- 6.2 List other user authentication optionsPractice
6.3 Describe the steps to enable multifactor authentication in SplunkIn the bank
Getting Data In
5%of exam7.1 Describe the basic settings for an inputIn the bank
- 7.2 List Splunk forwarder typesPractice
7.3 Configure the forwarderIn the bank
7.4 Add an input to UF using CLIIn the bank
Distributed Search
10%of exam- 8.1 Describe how distributed search worksPractice
8.2 Explain the roles of the search head and search peersIn the bank
8.3 Configure a distributed search groupIn the bank
- 8.4 List search head scaling optionsPractice
Getting Data In – Staging
5%of examConfiguring Forwarders
5%of examForwarder Management
10%of exam11.1 Explain the use of deployment managementIn the bank
11.2 Describe Splunk Deployment ServerIn the bank
11.3 Manage forwarders using deployment appsIn the bank
11.4 Configure deployment clientsIn the bank
11.5 Configure client groupsIn the bank
- 11.6 Monitor forwarder management activitiesPractice
Monitor Inputs
5%of exam12.1 Create file and directory monitor inputsIn the bank
- 12.2 Use optional settings for monitor inputsPractice
12.3 Deploy a remote monitor inputIn the bank
Network and Scripted Inputs
5%of exam13.1 Create network (TCP and UDP) inputsIn the bank
- 13.2 Describe optional settings for network inputsPractice
- 13.3 Create a basic scripted inputPractice
Agentless Inputs
5%of examFine Tuning Inputs
5%of examParsing Phase and Data
5%of exam16.1 Understand the default processing that occurs during parsingIn the bank
16.2 Optimize and configure event line breakingIn the bank
- 16.3 Explain how timestamps and time zones are extracted or assigned to eventsPractice
16.4 Use Data Preview to validate event creation during the parsing phaseIn the bank
Manipulating Raw Data
5%of exam17.1 Explain how data transformations are defined and invokedIn the bank
17.2 Use transformations with props.conf and transforms.conf to: ● Mask or delete raw data as it is being indexed ● Override sourcetype or host based upon event values ● Route events to specific indexes based on event content ● Prevent unwanted events from being indexedIn the bank
17.3 Use SEDCMD to modify raw dataIn the bank
Objectives marked Practice open a page of original questions written for that objective, each with a full explanation cited to Splunk documentation.
Keep reading
Enterprise Certified Admin practice questions
Free sample questions with the full explanation on every answer.
Free Enterprise Certified Admin practice test
Ten real questions, playable now. No account, no card.
Enterprise Certified Admin passing score
The exact cut score, what kind of number it is, and the retake terms.
How hard is Enterprise Certified Admin?
An honest difficulty read from the format, the clock and the weights.