Exam objectives

Enterprise Certified Admin

Splunk Enterprise Certified Admin exam objectives

The published blueprint is the contract: the exam can only test what is on this list. Domains carry their official weightings, and objectives with a practice page link straight to questions written for that objective.

Titles and weightings from the official objectives. Splunk exam page

Splunk Admin Basics

5%of exam

License Management

5%of exam

Splunk Configuration Files

5%of exam

Splunk Indexes

10%of exam
  • 4.1 Describe index structureIn the bank

  • 4.2 List types of index bucketsIn the bank

  • 4.3 Check index data integrityIn the bank

  • 4.4 Describe indexes.conf optionsPractice
  • 4.5 Describe the fishbucketIn the bank

  • 4.6 Apply a data retention policyIn the bank

Splunk User Management

5%of exam

Splunk Authentication Management

5%of exam

Getting Data In

5%of exam

Distributed Search

10%of exam

Getting Data In – Staging

5%of exam

Configuring Forwarders

5%of exam

Forwarder Management

10%of exam
  • 11.1 Explain the use of deployment managementIn the bank

  • 11.2 Describe Splunk Deployment ServerIn the bank

  • 11.3 Manage forwarders using deployment appsIn the bank

  • 11.4 Configure deployment clientsIn the bank

  • 11.5 Configure client groupsIn the bank

  • 11.6 Monitor forwarder management activitiesPractice

Monitor Inputs

5%of exam

Network and Scripted Inputs

5%of exam

Agentless Inputs

5%of exam

Fine Tuning Inputs

5%of exam

Parsing Phase and Data

5%of exam

Manipulating Raw Data

5%of exam
  • 17.1 Explain how data transformations are defined and invokedIn the bank

  • 17.2 Use transformations with props.conf and transforms.conf to: ● Mask or delete raw data as it is being indexed ● Override sourcetype or host based upon event values ● Route events to specific indexes based on event content ● Prevent unwanted events from being indexedIn the bank

  • 17.3 Use SEDCMD to modify raw dataIn the bank

Objectives marked Practice open a page of original questions written for that objective, each with a full explanation cited to Splunk documentation.

Keep reading

Every guide and cost breakdown, by vendor