Splunk Cloud Certified Admin (SPLK-1005) Preparation Details
The Splunk Cloud Certified Admin (SPLK-1005) exam tests your ability to configure inputs, forwarders, indexes, and users within a Splunk Cloud Platform deployment. This guide maps every domain and skill from the official exam blueprint to verified Splunk documentation so you can study each topic in order. You can also explore more Splunk certification study guides on the Splunk Certifications to keep building your skills.
Splunk Cloud Certified Admin Materials
1.0 Splunk Cloud Overview 5%
1.1 Describe Cloud topology
Splunk Cloud Platform Service Details
Welcome to the Splunk Cloud Platform Admin Manual
1.2 Describe tasks managed by the Splunk cloud administrator
Welcome to the Splunk Cloud Platform Admin Manual
Introduction to the Cloud Monitoring Console
Splunk Cloud Platform Service Details
1.3 List the primary differences between Splunk Cloud and Splunk Enterprise
Splunk Cloud Platform Service Details
Welcome to the Splunk Cloud Platform Admin Manual
1.4 List differences between Self-Service Cloud and Managed Cloud
Splunk Cloud Platform Service Details
Welcome to the Splunk Cloud Platform Admin Manual
2.0 Index Management 5%
2.1 Define a Splunk index
Manage Splunk Cloud Platform indexes
2.2 Create indexes in cloud
Manage Splunk Cloud Platform indexes
2.3 Delete data from an index
Manage Splunk Cloud Platform indexes
2.4 Monitor indexing activities
Introduction to the Cloud Monitoring Console
Use the monitoring console to view indexing performance
Manage Splunk Cloud Platform indexes
3.0 User Authentication and Authorization 5%
3.1 Administer Splunk user roles
3.2 Integrate Splunk with LDAP, Active Directory, or SAML
Set up user authentication with LDAP
Configure single sign-on with SAML
4.0 Splunk Configuration Files 5%
4.1 Review Splunk configuration files and directories
4.2 Review configuration file precedence
4.3 Review index and search time processes
5.0 Getting Data in Cloud 15%
5.1 List Splunk forwarder types
5.2 Describe the role of forwarders
About forwarding and receiving
5.3 Configure a forwarder to Splunk Cloud
How to forward data to Splunk Cloud Platform
Install and configure the Splunk Cloud Platform universal forwarder credentials package
5.4 Test the forwarder connection
Troubleshoot forwarder/receiver connection
5.5 Describe optional forwarder settings
Configure forwarders with outputs.conf
6.0 Forwarder Management 5%
6.1 Describe Splunk Deployment Server
About deployment server and forwarder management
6.2 Explain the use of forwarder management
About deployment server and forwarder management
6.3 Configure forwarders to be deployment clients
6.4 Managing forwarders using deployment apps
7.0 Monitor Inputs 15%
7.1 Describe the Splunk process for inputting data
How Splunk Enterprise handles your data
7.2 Create file and directory monitor inputs
Monitor files and directories with inputs.conf
7.3 Use optional settings for monitor inputs
Monitor files and directories with inputs.conf
8.0 Network and Other Inputs 10%
8.1 Create network (TCP and UDP) inputs
Get data from TCP and UDP ports
8.2 Create a basic scripted input
Get data from APIs and other remote data interfaces through scripted inputs
8.3 Describe optional settings for network inputs
Get data from TCP and UDP ports
8.4 Identify Windows input types and uses
Monitor Windows data with the Splunk platform
Monitor Windows event log data with Splunk Cloud Platform
8.5 Use the HTTP Event Collector (HEC) to get data into Splunk
Set up and use HTTP Event Collector in Splunk Web
Format events for HTTP Event Collector
9.0 Fine-tuning Inputs 5%
9.1 Describe the default processing that occurs during the input phase
How Splunk Enterprise handles your data
9.2 Configure input phase options, such as sourcetype fine-tuning and character set encoding
Configure character set encoding
Configure rule-based source type recognition
10.0 Parsing Phase and Data Preview 10%
10.1 Describe the default processing that occurs during parsing
10.2 Optimize and configure event line breaking
10.3 Explain how timestamps and time zones are extracted or assigned to events
Configure timestamp recognition
Specify time zones for timestamps
10.4 Use Data Preview to validate event creation during the parsing phase
11.0 Manipulating Raw Data 10%
11.1 Explain how data transformations are defined and invoked
11.2 Use transformations with props.conf and transforms.conf to modify raw data
11.3 Use SEDCMD to modify raw data
12.0 Installing and Managing Apps 5%
12.1 Review the process for installing apps
Install apps on your Splunk Cloud Platform deployment
12.2 Describe private apps
Manage private apps on your Splunk Cloud Platform deployment
12.3 Describe how apps are managed
Install apps on your Splunk Cloud Platform deployment
13.0 Working with Splunk Cloud Support 5%
13.1 Isolate problems before contacting Splunk Cloud Support
What’s in the Troubleshooting Manual?
13.2 Define the process for working with Splunk Cloud Support
How to file a great Support case
Wrapping Up Splunk Cloud Certified Admin
This guide walked through all 13 domains of the Splunk Cloud Certified Admin (SPLK-1005) blueprint, from cloud topology and index management through forwarders, inputs, parsing, and Support case handling. Working through each linked topic in order will build the practical administration skills the exam expects. You can also explore more Splunk certification study guides on the Splunk Certifications to keep building your skills. Have a question or tip? Leave a comment below.
Receive Updates on Splunk Cloud Certified Admin Exam
Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.